Directory Traversal Vulnerability in Atlantis Self-Hosted Application
CVE-2026-64679

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-64679?

The Atlantis application, a self-hosted golang tool for managing Terraform pull requests, has a directory traversal vulnerability affecting versions from 0.19.8 to 0.45.0. The issue arises from inadequate validation of user-controlled workspace values, potentially allowing an attacker to escape from the intended directory structure. This flaw can lead to unauthorized file system manipulations, including the ability to delete, create, or alter directories that the Atlantis process can access. Such actions can compromise the integrity of the system or lead to a denial of service. The vulnerability has been addressed in Atlantis version 0.45.0.

Affected Version(s)

atlantis >= 0.19.8, < 0.45.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.