Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This issue has been patched in version 0.93.1.

Project Subscriptions

Vendors Products
Terraform-provider-proxmox Subscribe
Terraform Provider Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gwch-7m8v-7544 terraform-provider-proxmox has insecure sudo recommendation in the documentation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 11 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Bpg terraform Provider
CPEs cpe:2.3:a:bpg:terraform_provider:*:*:*:*:*:proxmox_virtual_environment:*:*
Vendors & Products Bpg terraform Provider
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 05 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Bpg
Bpg terraform-provider-proxmox
Vendors & Products Bpg
Bpg terraform-provider-proxmox

Wed, 04 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This issue has been patched in version 0.93.1.
Title terraform-provider-proxmox has insecure sudo recommendation in the documentation
Weaknesses CWE-1188
CWE-22
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-05T21:05:30.910Z

Reserved: 2026-02-02T18:21:42.485Z

Link: CVE-2026-25499

cve-icon Vulnrichment

Updated: 2026-02-05T21:05:17.064Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-04T21:16:01.043

Modified: 2026-02-11T19:17:14.537

Link: CVE-2026-25499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-05T11:39:30Z

Weaknesses