Ghostwire

CVE-2026-74796: OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization....

HIGH CVSS 0.0

Published: August 16, 2026 | Last Modified: August 16, 2026

Description

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References