CVE-2026-104994
CVSS Score
2.5
EPSS Score
0.0%
EPSS Percentile
0th
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
| CWE | CWE-24 |
| Vendor | aquasec |
| Product | trivy |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for aquasec trivy
Be the first to know when new low vulnerabilities affecting aquasec trivy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
aquasec / Trivy
0 < 0.71.0
References
github.com: https://github.com/aquasecurity/trivy/security/advisories/GHSA-87hp-4m93-274g github.com: https://github.com/aquasecurity/trivy/commit/9d91b888cf63023e9c09b64259a4c1cea8dfe993 github.com: https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md github.com: https://github.com/aquasecurity/trivy/pull/10664