PT-2026-73163 · Opentofu · Opentofu
CVE-2026-74796
·
Published
2026-06-23
·
Updated
2026-08-17
CVSS v4.0
7.0
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenTofu versions prior to 1.11.7
Description
During initialization, the software fails to validate existing symlinks within the provider cache directory. This allows an attacker to place a malicious symlink in a trusted working directory, causing the
tofu init command to write provider package contents to arbitrary filesystem locations outside the working tree.Recommendations
Update to version 1.11.7 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opentofu