Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in Trivy Terraform Filesystem Functions |
Fri, 02 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output. | |
| First Time appeared |
Aquasec
Aquasec trivy |
|
| Weaknesses | CWE-24 | |
| CPEs | cpe:2.3:a:aquasec:trivy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aquasec
Aquasec trivy |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-02T19:52:36.831Z
Reserved: 2026-10-02T19:52:35.969Z
Link: CVE-2026-104994
No data.
Status : Deferred
Published: 2026-10-02T20:17:01.663
Modified: 2026-10-02T20:17:01.783
Link: CVE-2026-104994
No data.
OpenCVE Enrichment
Updated: 2026-10-02T22:30:19Z
Weaknesses