CRITICAL
vectordotdev
CVE published 2026-09-22
CVE-2026-77621
CVE-2026-77621 is a critical vulnerability in Vector, a high-performance observability data pipeline, affecting versions 0.10.0 through 0.56.0. The issue allows an attacker to write to arbitrary files on the system by manipulating event fields used in the file sink's path template. This can lead to sensitive file modification and potential code execution. The vulnerability is fixed in version 0.57.0.