Database/Control plane, storage & DevOps
Terragrunt: malicious module manifest deletes files outside the module cache during cleanup
Impact
Terragrunt trusts the paths recorded in a downloaded module's .terragrunt-module-manifest, so a hostile or compromised external module can list absolute or ../ paths that cleanup then deletes - anything the Terragrunt process can write, before OpenTofu or Terraform even runs. This is a deletion-only primitive: no code execution, no data read, but it can wipe local source, state configuration, or credentials staged in a CI workspace. For a fleet operator this matters where Terragrunt runs the infrastructure pipeline that provisions and reconfigures GPU nodes: a poisoned upstream module can break the pipeline that is your only path to change cluster state.
Who can reach it
Anyone who controls a Terraform/OpenTofu module your Terragrunt runs pull in, including an upstream registry or repo that gets compromised. No authentication to your systems is needed - the module just has to be referenced.
What to do
Upgrade Terragrunt to 1.0.4 and re-run pipelines with the new binary; it is a CLI replacement in the CI image, no service restart or node work. Meanwhile, pin external modules to reviewed commits and run Terragrunt as a low-privilege user in a disposable workspace so a deletion cannot reach anything but the job checkout.
References
Related entries
- Inspektor Gadget: crafted ld.so.cache in a container stalls the container-start hook cluster-wideCVE-2026-53941 · Inspektor Gadget (uprobe ld.so.cache parser, pkg/uprobetracer)Medium
- Renovate: minimumReleaseAge is not applied to digest updates, so fresh dependency digests reach CI earlyCVE-2026-88884 · Renovate (minimumReleaseAge enforcement for digest updates)Medium
- Schneider Electric StruxureWare Data Center Expert before 7.4.0: Passwords held in cleartext in RAM on the DCIMCVE-2017-8371 · Schneider Electric StruxureWare Data Center Expert before 7.4.0Medium
- RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)CVE-2020-12355 · RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)Medium
- Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMeCVE-2020-13799 · Replay Protected Memory Block (RPMB) protocol as specified for eMMC, UFS and ALL versions of NVMe - multi-vendor…Medium
- IBM Spectrum Scale Container Native Storage Access (CSI volume handling): Anyone who can create a pod plus a PV/PVCCVE-2022-40607 · IBM Spectrum Scale Container Native Storage Access (CSI volume handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.