Junglewise Threat Intelligence

CVE-2026-5061: HashiCorp consul-template sandbox path bypass in file helper

CVE-2026-5061 · Severity: medium · CVSS 4.7 · Published 2026-05-12

Technologies: HashiCorp Consul-Template. Vendors: HashiCorp.

Executive brief

HashiCorp consul-template is a tool used to manage configuration files by automatically updating them when data changes in HashiCorp Consul or Vault. A security flaw in the tool's file-handling component could allow a local user to bypass security restrictions and read sensitive files on the host system that they should not have access to. This could lead to the exposure of private configuration data or system secrets, potentially compromising the security of the underlying infrastructure.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) vulnerability exists in the 'file' template helper of consul-template. While the helper enforces a 'sandbox_path' during initial template evaluation, a subsequent dependency fetch reads the original input path without re-validating it against the sandbox restrictions. An attacker with local access can exploit this by replacing a legitimate file with a symlink after the initial check but before the fetch occurs (CWE-59). This allows the attacker to read files outside the sandbox. If the symlink is restored to a safe target before the next render cycle, the bypass may remain undetected while the template continues to use the cached out-of-sandbox content. The issue is fixed in version 0.42.0.

Affected products

  • HashiCorp consul-template < 0.42.0

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-12: patched: Fixed in version 0.42.0

References

Related threats