PT-2026-96794 · Vector · Vector
CVE-2026-77621
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Vector versions 0.10.0 through 0.56.0
Description
The file sink renders its templated path from event fields and opens the result without confining it to an intended directory. If an untrusted source provides an event field used by the path template, the value may contain an absolute path or parent-directory traversal. This allows the application to create parent directories and create or overwrite files outside the intended location using the privileges of the Vector process. Such file writes can modify sensitive files and potentially lead to code execution if a scheduled task, authorization file, or subsequently executed script is targeted.
Recommendations
Update to version 0.57.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vector