PT-2026-40036 · Hashicorp · Consul-Template

Published

2026-05-12

·

Updated

2026-05-14

·

CVE-2026-5061

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions consul-template versions prior to 0.42.0
Description A sandbox path bypass exists in the file template helper, which may allow an attacker to read files located outside of the intended sandbox directory.
Recommendations Update to version 0.42.0.

Fix

Link Following

Weakness Enumeration

Related Identifiers

BIT-CONSUL-2026-5061
CVE-2026-5061

Affected Products

Consul-Template