PT-2026-96794 · Vector · Vector

CVE-2026-77621

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Vector versions 0.10.0 through 0.56.0
Description The file sink renders its templated path from event fields and opens the result without confining it to an intended directory. If an untrusted source provides an event field used by the path template, the value may contain an absolute path or parent-directory traversal. This allows the application to create parent directories and create or overwrite files outside the intended location using the privileges of the Vector process. Such file writes can modify sensitive files and potentially lead to code execution if a scheduled task, authorization file, or subsequently executed script is targeted.
Recommendations Update to version 0.57.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77621
GHSA-6342-XWVW-C637

Affected Products

Vector