CVE-2026-14361: Consul-template is vulnerable to path redirection in writeToFile through symlink attack
The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
consul-templateto a version that resolves this vulnerability.Fixed in 0.42.1Patch CVE-2026-14361
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14361?
The severity of CVE-2026-14361 is medium, with a CVSS score of 4.7.
How do I fix CVE-2026-14361?
To fix CVE-2026-14361, upgrade to consul-template version 0.42.1 or later.
What type of attack does CVE-2026-14361 involve?
CVE-2026-14361 involves a symlink attack that allows path redirection in the writeToFile function.
What software is affected by CVE-2026-14361?
CVE-2026-14361 affects the HashiCorp consul-template library prior to version 0.42.1.
What is the potential impact of CVE-2026-14361?
The potential impact of CVE-2026-14361 includes unauthorized file writes outside the intended directory or overwriting of existing files.