{"id":"CVE-2026-14361","summary":"Consul-template is vulnerable to path redirection in writeToFile through symlink attack","details":"The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.","modified":"2026-07-15T02:17:19.412602916Z","published":"2026-07-08T20:11:32.799Z","database_specific":{"cwe_ids":["CWE-59"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14361.json","cna_assigner":"HashiCorp"},"references":[{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2026-20-consul-template-vulnerable-to-path-redirections-in-writetofile/77559"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14361.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14361"},{"type":"PACKAGE","url":"https://github.com/hashicorp/consul-template"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashicorp/consul-template","events":[{"introduced":"b9b30140a200a33734c610302c244abe39fc8477"},{"fixed":"ae285948d54c13ddc9dcb57d70d36c0ef08943a7"}],"database_specific":{"extracted_events":[{"introduced":"0.1.0"},{"fixed":"0.42.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.42.0","v0.41.4","v0.41.3","v0.41.2","v0.40.0","v0.39.1","v0.39.0","v0.38.1","v0.38.0","v0.37.6","v0.37.5","v0.37.4","v0.37.3","v0.37.2","v0.37.1","v0.37.0","v0.36.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","v0.31.0","v0.30.0","v0.29.6","v0.29.5","v0.29.4","v0.29.3","v0.29.2","v0.27.2","v0.29.1","v0.29.0","v0.28.0","v0.27.1","v0.27.0","v0.26.0","v0.25.2","v0.25.1","v0.25.0","v0.24.1","v0.24.0","v0.23.0","v0.22.1","v0.22.0","v0.21.3","v0.21.2","v0.21.1","v0.21.0","v0.20.1","v0.20.0","v0.19.5","v0.19.4","v0.19.3","v0.19.2","v0.19.1","v0.19.0","v0.18.5","v0.18.4","v0.18.3","v0.18.2","v0.18.1","v0.18.0","v0.18.0-rc3","v0.18.0-rc1","v0.16.0","v0.16.0-rc1","v0.15.0","v0.14.0","v0.13.0","v0.12.2","v0.12.1","v0.12.0","v0.11.1","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.5","v0.6.1","v0.6.0","v0.5.1","v0.5.0","v0.4.0","v0.3.1","v0.3.0","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14361.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}