Description
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 02 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output. | |
| First Time appeared |
Aquasec
Aquasec trivy |
|
| Weaknesses | CWE-24 | |
| CPEs | cpe:2.3:a:aquasec:trivy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aquasec
Aquasec trivy |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-02T19:52:36.831Z
Reserved: 2026-10-02T19:52:35.969Z
Link: CVE-2026-104994
No data.
Status : Deferred
Published: 2026-10-02T20:17:01.663
Modified: 2026-10-02T20:17:01.783
Link: CVE-2026-104994
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-24
Path Traversal: '../filedir'