Directory Traversal Vulnerability in Atlantis Self-Hosted Application
CVE-2026-64679
8.1HIGH
What is CVE-2026-64679?
The Atlantis application, a self-hosted golang tool for managing Terraform pull requests, has a directory traversal vulnerability affecting versions from 0.19.8 to 0.45.0. The issue arises from inadequate validation of user-controlled workspace values, potentially allowing an attacker to escape from the intended directory structure. This flaw can lead to unauthorized file system manipulations, including the ability to delete, create, or alter directories that the Atlantis process can access. Such actions can compromise the integrity of the system or lead to a denial of service. The vulnerability has been addressed in Atlantis version 0.45.0.
Affected Version(s)
atlantis >= 0.19.8, < 0.45.0
