Symlink Vulnerability in Infracost's File Handling
CVE-2026-71493

5.9MEDIUM

Key Information:

Vendor

Infracost

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-71493?

Infracost's file handling operations exhibit a symlink vulnerability that could allow unintended file access. The affected functions, such as readFile and pathExists, improperly handle symlinks, allowing paths to resolve outside of expected directories. This can lead to sensitive information exposure, especially in workflows involving repository secrets. The issue is addressed in version 0.10.45, which rectifies the handling of intermediate directory symlinks to prevent unauthorized file access.

Affected Version(s)

infracost < 0.10.45

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.