PT-2026-104433 · Aqua Security · Trivy

CVE-2026-104994

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trivy versions prior to 0.71.0
Description Directory traversal is possible in Terraform filesystem functions when accessing pathnames located above the scan root. This issue occurs during misconf scanning of untrusted input, such as Terraform configurations provided in third-party pull requests. An adversary may be able to view sensitive data values within the scan output if such data exists at the unintended pathnames.
Recommendations Update to version 0.71.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104994
GHSA-87HP-4M93-274G

Affected Products

Trivy