Remote Token Disclosure in Infracost Cloud Cost Management
CVE-2026-71494
5.9MEDIUM
What is CVE-2026-71494?
Infracost, a tool providing cloud cost intelligence, had a vulnerability that allowed untrusted Terraform input to attach tokens to questionable hostnames. This could enable attackers to intercept tokens during a CI run when scanning compromised Terraform configurations. The flaw primarily affected workflows involving pull_request_target or similar pull requests. The vulnerability has been addressed in the release of version 0.10.45, ensuring safe handling of tokens and reducing the risk of unauthorized access.
Affected Version(s)
infracost < 0.10.45
