Terraform WinDNS Provider improperly sanitizes input variables in `windns_record` in github.com/nrkno/terraform-provider-windns
Terraform WinDNS Provider improperly sanitizes input variables in `windns_record` in github.com/nrkno/terraform-provider-windns
02 / AFFECTED SOFTWARE
Affected packages
8 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Terraform WinDNS Provider improperly sanitizes input variables in `windns_record` in github.com/nrkno/terraform-provider-windns
## Impact: A security issue has been found in `terraform-provider-windns` before version `1.0.5`. The `windns_record` resource did not santize the input variables. This can lead to authenticated command injection in the underlyding powershell command prompt. ## Patches: [`83ef736 (fix: better input validation)`](https://github.com/nrkno/terraform-provider-windns/commit/c76f69610c1b502f90aaed8c4f102194530b5bce) ## Fixed versions: - `v1.0.5`
Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. This could lead to authenticated command injection in the underlyding powershell command prompt. Version 1.0.5 contains a fix for the issue.
05 / REFERENCES
Further evidence
- https://github.com/nrkno/terraform-provider-windns/commit/c76f69610c1b502f90aaed8c4f102194530b5bce
- https://github.com/nrkno/terraform-provider-windns/security/advisories/GHSA-4vgf-2cm4-mp7c
- https://nvd.nist.gov/vuln/detail/CVE-2025-46735
- https://github.com/nrkno/terraform-provider-windns
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46735.json