Security Advisory

CVE-2026-14361

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-08 20:11:32
Last updated 2026-07-08 20:37:56
Assigner HashiCorp
CVSS score 4.7
State PUBLISHED

Description

The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.