Intel

AIKIDO-2025-10923

github.com/influxdata/telegraf is vulnerable to External Control of System or Configuration Setting

External Control of System or Configuration Setting Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 11, 2025

18

Low Risk

This Affects:

GOgithub.com/influxdata/telegraf
0.1.0 - 1.36.4
Fixed in 1.37.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package have a vulnerability that allows environment variables to be processed into raw configuration text without strict TOML enforcement. It can lead to unexpected type parsing and configuration manipulation. An attacker can manipulate these variables and inject malicious values, potentially bypassing security controls and altering Telegraf's configuration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/influxdata/telegraf is vulnerable to External Control of System or Configuration Setting in versions 0.1.0 - 1.36.4.

How to fix this

Upgrade the github.com/influxdata/telegraf library to the patch version.