๐Ÿ” CVE Alert

CVE-2026-45099

UNKNOWN 0.0

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileManifest.Clean() in internal/util/file.go. A malicious or compromised external module can place absolute or traversal paths in the manifest, causing cleanup to delete files outside the module cache that are accessible to the Terragrunt process before OpenTofu or Terraform executes. This deletion-only primitive can remove local source code or configuration and disrupt CI/CD pipelines. This issue is fixed in version 1.0.4.

CWE CWE-22
Vendor gruntwork-io
Product terragrunt
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for gruntwork-io terragrunt

Be the first to know when new unknown vulnerabilities affecting gruntwork-io terragrunt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gruntwork-io / terragrunt
< 1.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gruntwork-io/terragrunt/security/advisories/GHSA-8394-6f8r-whxg github.com: https://github.com/gruntwork-io/terragrunt/pull/6032 github.com: https://github.com/gruntwork-io/terragrunt/commit/3d6f10d6bccc851c6506a307a0b8675e0346e65e github.com: https://github.com/gruntwork-io/terragrunt/releases/tag/v1.0.4