Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This issue has been patched in version 0.93.1.
References
| Link | Resource |
|---|---|
| https://github.com/bpg/terraform-provider-proxmox/commit/bd604c41a31e2a55dd6acc01b0608be3ea49c023 | Patch |
| https://github.com/bpg/terraform-provider-proxmox/security/advisories/GHSA-gwch-7m8v-7544 | Exploit Vendor Advisory |
| https://github.com/bpg/terraform-provider-proxmox/security/advisories/GHSA-gwch-7m8v-7544 | Exploit Vendor Advisory |
Configurations
History
11 Feb 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bpg/terraform-provider-proxmox/commit/bd604c41a31e2a55dd6acc01b0608be3ea49c023 - Patch | |
| References | () https://github.com/bpg/terraform-provider-proxmox/security/advisories/GHSA-gwch-7m8v-7544 - Exploit, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Bpg terraform Provider
Bpg |
|
| CPE | cpe:2.3:a:bpg:terraform_provider:*:*:*:*:*:proxmox_virtual_environment:*:* |
05 Feb 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bpg/terraform-provider-proxmox/security/advisories/GHSA-gwch-7m8v-7544 - |
04 Feb 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-04 21:16
Updated : 2026-02-11 19:17
NVD link : CVE-2026-25499
Mitre link : CVE-2026-25499
CVE.ORG link : CVE-2026-25499
JSON object : View
Products Affected
bpg
- terraform_provider
