Junglewise Threat Intelligence

CVE-2026-14361: HashiCorp Consul-template path redirection in writeToFile helper

CVE-2026-14361 · Severity: medium · CVSS 4.7 · Published 2026-07-08

Technologies: HashiCorp Consul-Template. Vendors: HashiCorp.

Executive brief

HashiCorp Consul-template is a tool used to manage configuration files by automatically updating them when data changes in the Consul service. A security flaw in the tool's file-writing function allows an attacker with local access to redirect where files are saved. This could lead to sensitive information, such as security certificates or private keys, being written to unauthorized locations or overwriting critical system files, potentially compromising the security of the server.

Technical details

The writeToFile template helper in consul-template (versions prior to 0.42.1) fails to properly resolve and validate destination paths before writing rendered content. The function follows symbolic links, directory junctions, and other filesystem redirections without verifying if the final path resides within the intended directory (CWE-59). An attacker with local filesystem access can pre-position a symlink at the target path to redirect the output. This can result in the disclosure of sensitive data (like certificates or keys) to unauthorized locations or the overwriting of arbitrary files, especially if the process is running with elevated privileges. The issue is resolved in version 0.42.1.

Affected products

  • HashiCorp Consul-template 0.1.0 to 0.42.0

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References

Related threats