Vulnerability Description
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md
- https://github.com/aquasecurity/trivy/commit/9d91b888cf63023e9c09b64259a4c1cea8d
- https://github.com/aquasecurity/trivy/pull/10664
- https://github.com/aquasecurity/trivy/security/advisories/GHSA-87hp-4m93-274g
FAQ
What is CVE-2026-104994?
CVE-2026-104994 is a vulnerability with a CVSS score of 2.5 (LOW). Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (...
How severe is CVE-2026-104994?
CVE-2026-104994 has been rated LOW with a CVSS base score of 2.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-104994?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.