Database/Control plane, storage & DevOps
Trivy: Terraform filesystem functions read paths above the scan root during misconfig scans
Impact
Trivy's Terraform misconfiguration scanner evaluates filesystem functions without confining them to the scan root, so a Terraform configuration under scan can reference paths outside the checkout and have their contents surface in scan output. In a CI pipeline that runs misconfig scanning on untrusted contributions, a third-party pull request can read files from the runner - tokens, kubeconfigs, registry credentials - and exfiltrate them through the scan report, which is typically published back to the PR. The blast radius is whatever the scanner's runner holds, which on a fleet CI host is often credentials for the clusters it deploys to. Low severity as scored, but it matters precisely where scanning is pointed at untrusted input.
Who can reach it
Anyone who can get a Terraform configuration scanned - in practice, an outside contributor opening a pull request against a repository whose CI runs Trivy misconfig scanning on PR content and surfaces the output. No access to the runner itself is needed.
What to do
Upgrade Trivy to 0.71.0 or later in CI images and runner toolchains. Until then, avoid running misconfig scanning on untrusted pull-request content, or run it in a job with no credentials and no access to the rest of the runner filesystem. No service downtime: this is a scanner binary, replaced on the next pipeline run.
References
Related entries
- Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode): SR670 V2 servers built between roughly June 2021 and JulyCVE-2024-23591 · Lenovo ThinkSystem SR670 V2 (shipped in Manufacturing Mode)Low
- Linuxfabrik monitoring plugins: symlink attack on predictable /tmp SQLite caches lets a local user write as rootCVE-2026-53759 · linuxfabrik-lib db_sqlite.py (Monitoring Plugins cache databases in /tmp)Low
- Grafana Alerting: Editor can exfiltrate contact point credentials by retargeting the test endpointCVE-2025-12141 · Grafana Alerting (contact point test, redacted secure settings)Low
- QCT (Quanta Cloud Technology) server security centre: QCT firmware is unmeasurable from public data despiteNCVD-2026-012-qct-quanta-cloud-technology-serv · QCT (Quanta Cloud Technology) server security centreUnscored
- Supermicro's public security advisory portal itself: An operator cannot programmatically track Supermicro firmwareNCVD-2026-013-supermicro-s-public-security-adv · Supermicro's public security advisory portal itselfUnscored
- Tyan / MiTAC Computing PSIRT: For Tyan, this vendor's firmware is unmeasurable from public dataNCVD-2026-014-tyan-mitac-computing-psirt · Tyan / MiTAC Computing PSIRTUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.