Skip to content
HashiCorpCVE-2026-14361

HashiCorp Tooling: link following

Medium4.7CVE-2026-14361 · Published Jul 8, 2026 · updated Jul 9, 2026

The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Tooling
Product
>= 0.1.0, < 0.42.10.42.1
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Nomad: improper authorization
Medium4.2Jul 8
HashiCorp Nomad: missing authorization
High7.7Jul 8
HashiCorp Nomad: link following
High8.7Jul 8
HashiCorp Shared library: denial of service
Medium4.9Jul 8
HashiCorp Terraform Enterprise: path traversal
High7.7Jul 6
HashiCorp Vault: path traversal
Medium4.4Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.