VYPR
Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026

Consul-template is vulnerable to path redirection in writeToFile through symlink attack

CVE-2026-14361

Description

The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.