CVE-2026-104994 Details
Description
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
A directory traversal vulnerability has been identified in Trivy versions prior to 0.71.0. This issue arises within Terraform filesystem functions that attempt to access pathnames above the designated scan root. The vulnerability is particularly concerning when scanning untrusted input, such as third-party Terraform configurations, as it may lead to the exposure of sensitive data located at unintended pathnames.
Users can update to Trivy version 0.71.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md | [email protected] | Release NotesVendor |
| https://github.com/aquasecurity/trivy/commit/9d91b888cf63023e9c09b64259a4c1cea8dfe993 | [email protected] | Source CodeVendor |
| https://github.com/aquasecurity/trivy/pull/10664 | [email protected] | Issue TrackingVendor |
| https://github.com/aquasecurity/trivy/security/advisories/GHSA-87hp-4m93-274g | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-24 | Path Traversal: '../filedir' | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Aqua Security Trivy | < 0.71.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 2, 2026 | New CVE Received | [email protected] |
Volerion