Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This issue has been patched in version 0.93.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gwch-7m8v-7544 terraform-provider-proxmox has insecure sudo recommendation in the documentation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Feb 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Bpg
Bpg terraform-provider-proxmox
Vendors & Products Bpg
Bpg terraform-provider-proxmox

Wed, 04 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This issue has been patched in version 0.93.1.
Title terraform-provider-proxmox has insecure sudo recommendation in the documentation
Weaknesses CWE-1188
CWE-22
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-04T20:31:17.316Z

Reserved: 2026-02-02T18:21:42.485Z

Link: CVE-2026-25499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-04T21:16:01.043

Modified: 2026-02-04T21:16:01.043

Link: CVE-2026-25499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-05T11:39:30Z

Weaknesses