Trivy Terraform filesystem functions read paths above the scan root
Fixed in: Trivy 0.71.0
patched
details
Finding IDs
F-TRIVY-TF-FILE-001
CVE
CVE-2026-104994
Status
patched
Fixed in
Trivy 0.71.0
Note
The published CVE covers Trivy before 0.71.0 when Terraform filesystem functions access paths above the scan root during misconfiguration scanning of untrusted input. Exposure requires sensitive data at an unintended path and visibility of that value in scan output. The vendor advisory GHSA-87hp-4m93-274g remains closed and is not presented as a published advisory.
revalidated with a minimal Terraform file("../secret.txt") PoC through mapfs.WithUnderlyingRoot: Trivy v0.70.0 reads POC_SECRET from outside the scan root, while v0.71.0 and v0.71.2 block traversal with no file exists at ../secret.txt. upstream fix commit 9d91b888cf63 shipped in v0.71.0 and makes Terraform filesystem functions use a sandboxed FS without access to the underlying OS root. CVE-2026-104994 was published on 2026-10-02 for this Terraform filesystem-function issue.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.