Impact
Vector, a high‑performance observability data pipeline, allowed an untrusted source to control the rendering of file paths for its file sink. The path string was built from event fields without confinement to a base directory, permitting absolute paths or parent‑directory traversal. This permitted the creation or overwriting of files outside the intended location with the privileges of the Vector process, potentially modifying sensitive files and enabling code execution through affected scheduled tasks, authorization files, or subsequently executed scripts.
Affected Systems
The vulnerability affected versions of Vector from 0.10.0 through 0.57.0, distributed by vectordotdev. The file sink component was responsible for the path rendering flaw, and all users deploying Vector within this version range were impacted.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity for this flaw. While the EPSS score is currently unavailable, the lack of a KEV listing does not reduce the risk; attackers can supply malicious event data to create or modify files, potentially leading to privilege escalation or remote code execution. The attack is likely possible over any interface that allows arbitrary event data to reach the Vector instance.
OpenCVE Enrichment