PT-2026-79415 · Infracost · Infracost
CVE-2026-71494
·
Published
2026-08-21
·
Updated
2026-09-10
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Infracost versions prior to 0.10.45
Description
Infracost allows the attachment of a configured Terraform Cloud or registry token to a destination hostname derived from untrusted Terraform input without verifying if the host is trusted. This occurs within
internal/hcl/remote variables loader.go and request paths related to Terraform Cloud, remote-plan, and the Terragrunt registry. An attacker providing malicious Terraform input during a CI run that includes a token, such as through pull request target or a same-repository pull request, can redirect the request to a host under their control to disclose the token. Standard fork pull request workflows that do not use secrets are not affected.Recommendations
Update to version 0.10.45.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infracost