The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.
{
"cpes": [
"cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*"
],
"severity": "Medium"
}