GPU VulnDB

Database/Control plane, storage & DevOps

Trivy: Terraform filesystem functions read paths above the scan root during misconfig scans

CVSS 2.5CVE-2026-104994Control plane, storage & DevOpscurated

Impact

Trivy's Terraform misconfiguration scanner evaluates filesystem functions without confining them to the scan root, so a Terraform configuration under scan can reference paths outside the checkout and have their contents surface in scan output. In a CI pipeline that runs misconfig scanning on untrusted contributions, a third-party pull request can read files from the runner - tokens, kubeconfigs, registry credentials - and exfiltrate them through the scan report, which is typically published back to the PR. The blast radius is whatever the scanner's runner holds, which on a fleet CI host is often credentials for the clusters it deploys to. Low severity as scored, but it matters precisely where scanning is pointed at untrusted input.

Who can reach it

Anyone who can get a Terraform configuration scanned - in practice, an outside contributor opening a pull request against a repository whose CI runs Trivy misconfig scanning on PR content and surfaces the output. No access to the runner itself is needed.

What to do

Upgrade Trivy to 0.71.0 or later in CI images and runner toolchains. Until then, avoid running misconfig scanning on untrusted pull-request content, or run it in a job with no credentials and no access to the rest of the runner filesystem. No service downtime: this is a scanner binary, replaced on the next pipeline run.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.