Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.
References
Configurations
History
No history.
Information
Published : 2026-02-06 21:16
Updated : 2026-02-19 17:45
NVD link : CVE-2026-25628
Mitre link : CVE-2026-25628
CVE.ORG link : CVE-2026-25628
JSON object : View
Products Affected
qdrant
- qdrant
CWE
CWE-73
External Control of File Name or Path
