low · CVSS v3 2.5 · EPSS 0.00197
CVE-2026-104994
Trivy, a popular open-source vulnerability scanner, has a directory traversal flaw in Terraform filesystem functions. The bug allows an atta
Overview
Trivy, a popular open-source vulnerability scanner, has a directory traversal flaw in Terraform filesystem functions. The bug allows an attacker to read files outside the intended scan root when scanning untrusted Terraform configurations. This can expose sensitive data in scan results.
Description
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
Impact
Confidentiality: Sensitive files outside the scan root may be disclosed. Integrity: Scan results may be misleading if unexpected files are included. Availability: Not directly impacted. Defenders: Security teams using Trivy to scan Terraform configurations, especially in CI pipelines that ingest untrusted PRs.
Remediation
Upgrade Trivy to version 0.71.0 or later. If upgrade is not possible, configure the scanner to run in a restricted environment, disable Terraform filesystem functions, or sanitize input paths before scanning. Ensure CI pipelines only scan trusted code.
Risk context
Severity is low with CVSS v3 score 2.5 and EPSS 0.00197, indicating a very low probability of exploitation. However, the potential exposure of sensitive data warrants timely patching, especially in environments processing untrusted Terraform code.
Affected products
- Trivy 0.70.x
Scores
- Severity
- low
- CVSS v2
- 1
- CVSS v3
- 2.5
- CVSS v4
- —
- EPSS
- 0.00197