consultemplate 0.42.1: Path Redirection in writeToFile (CVE2026-14361)
CVE-2026-14361 Published on July 8, 2026

Consul-template is vulnerable to path redirection in writeToFile through symlink attack
The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.

NVD

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2026-14361 has been classified to as an insecure temporary file vulnerability or weakness.


Affected Versions

HashiCorp Tooling:

Exploit Probability

EPSS
0.11%
Percentile
1.25%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.