CVSS
6.1
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 16, 2026
Exploitability
No EPSS data available
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).