CVE-2026-55108 | KubeVela up to 1.9.13/1.10.8/1.11.0-alpha.3 Terraform Remote Configuration Loader capability.go GetTerraformConfigurationFromRemote terraform.path symlink
A vulnerability classified as critical was found in KubeVela up to 1.9.13/1.10.8/1.11.0-alpha.3. This affects the function GetTerraformConfigurationFromRemote of the file pkg/controller/utils/capability.go of the component Terraform Remote Configuration Loader. Executing a manipulation of the argument terraform.path can lead to symlink following.
The identification of this vulnerability is CVE-2026-55108. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.