Remote Token Disclosure in Infracost Cloud Cost Management
CVE-2026-71494

5.9MEDIUM

Key Information:

Vendor

Infracost

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-71494?

Infracost, a tool providing cloud cost intelligence, had a vulnerability that allowed untrusted Terraform input to attach tokens to questionable hostnames. This could enable attackers to intercept tokens during a CI run when scanning compromised Terraform configurations. The flaw primarily affected workflows involving pull_request_target or similar pull requests. The vulnerability has been addressed in the release of version 0.10.45, ensuring safe handling of tokens and reducing the risk of unauthorized access.

Affected Version(s)

infracost < 0.10.45

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.