CVE-2026-104994
Deferred Deferred - Pending Action

Path Traversal in Trivy via Terraform Filesystem Functions

Vulnerability report for CVE-2026-104994, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
aquasecurity trivy to 0.71.0 (exc)
aquasec trivy to 0.71.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-24 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Trivy before version 0.71.0 has a path traversal vulnerability in its Terraform filesystem functions. When scanning untrusted Terraform configurations, functions like file() or filebase64() could access files outside the intended scan directory using directory traversal sequences (e.g., ../). This happens because the filesystem allowed access above the scan root. The vulnerability could expose sensitive data if such files exist and are included in scan output.

Detection Guidance

To detect this vulnerability, scan Terraform configurations using Trivy version 0.71.0 or later. Use the command: trivy fs --security-checks misconf /path/to/terraform/config. Check for path traversal attempts in logs or output that reference parent directories (e.g., ../).

Verify Trivy version with: trivy --version. If using an older version, update Trivy to 0.71.0 or higher to ensure the fix is applied.

Impact Analysis

If you use Trivy to scan Terraform configurations from untrusted sources (e.g., third-party pull requests), an attacker could craft a Terraform file that uses path traversal to access sensitive files outside the scan directory. If those files are referenced in the configuration, their contents could be exposed in Trivy's scan output. This risk is higher when scanning subdirectories where shared files reside at the repository root.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements under GDPR (e.g., unauthorized data access) or HIPAA (e.g., exposure of protected health information). If scan outputs include sensitive data accessed via path traversal, organizations may fail to meet data protection obligations.

Mitigation Strategies

Upgrade Trivy to version 0.71.0 or later to apply the sandboxing fix for Terraform filesystem functions. This prevents path traversal by restricting file access to the scan root directory.

Scan Terraform configurations from the repository root to avoid false positives and ensure all files are within the intended scan boundary. Suppress checks only if necessary and after validation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104994. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart