CVE-2026-5061: Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack
The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5061?
The severity of CVE-2026-5061 has not been explicitly stated, but it involves a significant risk of information disclosure due to the exposed file access.
How do I fix CVE-2026-5061?
To fix CVE-2026-5061, upgrade your HashiCorp consul-template library to version 0.42.0 or later.
What versions of consul-template are affected by CVE-2026-5061?
Versions of HashiCorp consul-template prior to 0.42.0 are affected by CVE-2026-5061.
What kind of attack does CVE-2026-5061 describe?
CVE-2026-5061 describes a sandbox path bypass vulnerability that can be exploited via a symlink attack.
Can CVE-2026-5061 lead to data exposure?
Yes, CVE-2026-5061 may allow unauthorized reading of files outside the intended sandbox environment.