๐Ÿ” CVE Alert

CVE-2026-104994

LOW 2.5
CVSS Score
2.5
EPSS Score
0.0%
EPSS Percentile
0th

Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.

CWE CWE-24
Vendor aquasec
Product trivy
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for aquasec trivy

Be the first to know when new low vulnerabilities affecting aquasec trivy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

aquasec / Trivy
0 < 0.71.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/aquasecurity/trivy/security/advisories/GHSA-87hp-4m93-274g github.com: https://github.com/aquasecurity/trivy/commit/9d91b888cf63023e9c09b64259a4c1cea8dfe993 github.com: https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md github.com: https://github.com/aquasecurity/trivy/pull/10664