CVE-2026-14361: Hashicorp Tooling
Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.
The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.
Affected products
- Hashicorp Tooling: from 0.1.0, before 0.42.1 (fixed in 0.42.1)
Published 2026-07-08. Last modified 2026-07-09.