CVE-2025-6000 is a HashiCorp Vault vulnerability in audit device configuration handling. A privileged Vault operator in the root namespace with write access to the sys/audit endpoint can abuse the file audit device when a plugin directory is configured in Vault. By manipulating audit device settings, the attacker can write or overwrite files in the plugin directory and then have attacker-controlled content loaded as a plugin, resulting in arbitrary code execution on the underlying host running Vault. The issue is described as stemming from improper control over code generation/execution paths in the interaction between audit logging and plugin loading.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository is a compact Python proof-of-concept for CVE-2025-6000 affecting HashiCorp Vault audit backends when a plugin directory is configured. Its only code file, CVE-2025-6000.py, implements the full exploit workflow rather than merely checking for exposure. It communicates with Vault's HTTP API using an X-Vault-Token header, configures audit devices, and abuses attacker-controlled audit options to write an executable payload into the Vault plugin directory. It then obtains the plugin checksum either from a supplied SHA-256 value or by reconstructing candidate file bytes from a captured socket-audit stream. The script iterates plausible contiguous audit-record spans, hashes each reconstructed candidate, registers/mounts the corresponding plugin, and detects success using an integrated HTTP callback server. An integrated TCP server receives Vault's socket-audit output. The README documents root-token/equivalent privilege requirements, the affected Vault range, and optional cleanup. LICENSE is standard MIT text; README.md is documentation only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A HashiCorp Vault vulnerability enabling deletion of a critical key material file required to decrypt stored secrets, effectively rendering secrets unrecoverable (destructive impact).
A remote code execution vulnerability in HashiCorp Vault mentioned as part of the vendor's 2025 security history.
A remote code execution chain in HashiCorp Vault abusing audit logging and plugin handling to write an executable payload into the plugin directory and load it as a plugin, resulting in arbitrary code execution without memory corruption.
A privilege-related arbitrary code execution vulnerability in HashiCorp Vault that can allow a privileged operator to achieve host-level code execution via audit device configuration when a plugin directory is configured.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.