Directory Traversal Vulnerability in Terraform Filesystem Functions by Aqua Security
CVE-2026-104994

2.5LOW

Key Information:

Vendor

Aquasec

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104994?

Aqua Security's Trivy, prior to version 0.71.0, has a directory traversal vulnerability in its handling of Terraform filesystem functions. This issue arises when scans are conducted on untrusted input, particularly in instances where third-party configurations are involved. If sensitive information is present at unintended path locations, an attacker may access this data through the scan output. Such a vulnerability underscores the importance of thorough security practices when utilizing automation tools like Terraform.

Affected Version(s)

Trivy 0 < 0.71.0

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.