Symlink Following Vulnerability in OpenTofu by OpenTofu
CVE-2026-74796
7HIGH
What is CVE-2026-74796?
OpenTofu prior to version 1.11.7 demonstrates a serious flaw in its handling of symbolic links during the provider cache directory initialization. Attackers can exploit this vulnerability by placing a malicious symlink in a supposedly trusted working directory. This can lead to the execution of the 'tofu init' command, which writes provider package contents to arbitrary locations within the file system, potentially exposing sensitive data or compromising system integrity.
Affected Version(s)
opentofu 0 < 1.11.7
opentofu 1.11.7
