PatchSiren

vectordotdev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL vectordotdev CVE published 2026-09-22

CVE-2026-77621

CVE-2026-77621 is a critical vulnerability in Vector, a high-performance observability data pipeline, affecting versions 0.10.0 through 0.56.0. The issue allows an attacker to write to arbitrary files on the system by manipulating event fields used in the file sink's path template. This can lead to sensitive file modification and potential code execution. The vulnerability is fixed in version 0.57.0.