Hashicorp Vagrant vulnerabilities
6 known vulnerabilities affecting hashicorp/vagrant.
Total CVEs
6
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-34075MEDIUM≥ 2.2.10, < 2.4.72025-07-02
CVE-2025-34075 [MEDIUM] CWE-276 HashiCorp Vagrant has code injection vulnerability through default synced folders
HashiCorp Vagrant has code injection vulnerability through default synced folders
An authenticated virtual machine escape vulnerability exists in HashiCorp Vagrant versions 2.4.6 and below when using the default synced folder configuration. By design, Vagrant automatically mounts the host system’s project directory into the guest VM under /vagrant (or C:\vagrant on Windows). This in
ghsaosv
CVE-2024-10228LOWCVSS 3.3fixed in 1.0.232024-10-29
CVE-2024-10228 [LOW] CWE-732 CVE-2024-10228: The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path th
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
nvd
CVE-2023-5834HIGHCVSS 7.8fixed in 2.4.0≥ *, < 2.4.02023-10-27
CVE-2023-5834 [HIGH] CWE-1386 CVE-2023-5834: HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that coul
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
nvd
CVE-2022-42717HIGHCVSS 7.8fixed in 2.3.12022-10-11
CVE-2022-42717 [HIGH] CWE-284 CVE-2022-42717: An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.
nvd
CVE-2017-16777HIGHCVSS 7.8PoCv5.0.32017-11-16
CVE-2017-16777 [HIGH] CWE-427 CVE-2017-16777: If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root.
nvd
CVE-2017-16001HIGHCVSS 7.8PoCv5.0.12017-11-06
CVE-2017-16001 [HIGH] CWE-362 CVE-2017-16001: In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or mal
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
nvd