PT-2026-79415 · Infracost · Infracost

CVE-2026-71494

·

Published

2026-08-21

·

Updated

2026-09-10

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Infracost versions prior to 0.10.45
Description Infracost allows the attachment of a configured Terraform Cloud or registry token to a destination hostname derived from untrusted Terraform input without verifying if the host is trusted. This occurs within internal/hcl/remote variables loader.go and request paths related to Terraform Cloud, remote-plan, and the Terragrunt registry. An attacker providing malicious Terraform input during a CI run that includes a token, such as through pull request target or a same-repository pull request, can redirect the request to a host under their control to disclose the token. Standard fork pull request workflows that do not use secrets are not affected.
Recommendations Update to version 0.10.45.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71494
GHSA-6X6C-W9W9-HV4H
GO-2026-6437

Affected Products

Infracost