CVE-2026-104994

low

Description

Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.

References

https://github.com/aquasecurity/trivy/security/advisories/GHSA-87hp-4m93-274g

https://github.com/aquasecurity/trivy/pull/10664

https://github.com/aquasecurity/trivy/commit/9d91b888cf63023e9c09b64259a4c1cea8dfe993

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91789

Details

Source: Mitre, NVD

Published: 2026-10-02

Updated: 2026-10-05

Risk Information

CVSS v2

Base Score: 1

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 2.5

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Low

EPSS

EPSS: 0.00197