CVE-2025-12972 is a path traversal vulnerability in the Fluent Bit out_file plugin, affecting treasuredata fluent_bit. Attackers with network access can manipulate untrusted tag input to craft file paths, enabling them to write files outside the intended directory. This medium-severity vulnerability (CVSS 5.3) requires no user interaction and has a low impact on integrity, with no impact on confidentiality or availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.