Security Advisory

CVE-2026-5061

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-12 13:58:20
Last updated 2026-05-12 15:43:01
Assigner HashiCorp
CVSS score 4.7
State PUBLISHED

Description

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.