Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
Consul-template is vulnerable to path redirection in writeToFile through symlink attack
CVE-2026-14361
Description
The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.
Affected products
1- Range: <0.42.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.