Symlink Vulnerability in Infracost's File Handling
CVE-2026-71493
5.9MEDIUM
What is CVE-2026-71493?
Infracost's file handling operations exhibit a symlink vulnerability that could allow unintended file access. The affected functions, such as readFile and pathExists, improperly handle symlinks, allowing paths to resolve outside of expected directories. This can lead to sensitive information exposure, especially in workflows involving repository secrets. The issue is addressed in version 0.10.45, which rectifies the handling of intermediate directory symlinks to prevent unauthorized file access.
Affected Version(s)
infracost < 0.10.45
