Impact
A flaw in Checkov by Prisma Cloud allows a malicious attacker to place a specially crafted configuration file in a directory that Checkov scans, causing the tool to load the file automatically and execute code. This results in arbitrary code execution under the privileges of the Checkov process, enabling an attacker to take full control of the scanning environment. The weakness is classified as Improper Control of Resource Privileges (CWE‑829).
Affected Systems
Palo Alto Networks Checkov by Prisma Cloud versions 3.2.0 through 3.2.531 are affected. The vulnerability exists whenever these versions perform scans that include directories containing configuration files that are not explicitly supplied by the user.
Risk and Exploitability
The CVSS score of 2.4 indicates a low severity, and no EPSS score is available; the vulnerability is also not listed in CISA KEV. However, the risk remains significant because arbitrary code execution can occur whenever an unsuspecting user runs Checkov against a directory containing an attacker‑controlled file. The likely attack vector is local or by compromising a repository that includes a malicious configuration file, making the vulnerability especially relevant in CI/CD pipelines or when scanning untrusted codebases.
OpenCVE Enrichment