Directory Traversal Vulnerability in Terragrunt Tool by Gruntwork
CVE-2026-45099

6.9MEDIUM

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-45099?

Terragrunt, an orchestration tool designed for Infrastructure as Code, is susceptible to a directory traversal vulnerability in versions prior to 1.0.4. This issue arises from the tool's handling of the .terragrunt-module-manifest, which can be manipulated by a malicious external module. Such manipulation may lead to the deletion of files outside the designated module cache, posing significant risks to local source code and configuration files. Consequently, this vulnerability threatens to disrupt continuous integration and continuous deployment (CI/CD) pipelines, making timely updates essential for users relying on Terragrunt for their infrastructure management.

Affected Version(s)

terragrunt < 1.0.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.