Threat Advisory

Atlantis Workspace Handling Has Path Traversal Vulnerability

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-64679 is a path traversal vulnerability with affected versions or code paths, Atlantis could create, use, or remove/recreate out-of-bounds directories with the privileges of the Atlantis process user, before Terraform rejec with affected versions, code path, deployment configuration, and filesystem permissions, this may result in unintended directory creation, deletion, or reuse, integrity impact to wri in Atlantis workspace handling that allows out-of-bounds directory deletion/creation. Affected versions are >= 0.19.8 and < 0.45.0, which did not consistently validate user-controlled workspace values before using them to construct local workspace paths. A crafted workspace value containing path traversal segments could cause Atlantis to resolve workspace paths outside the intended per-pull workspace directory, creating, using, or removing/recreating out-of-bounds directories with the privileges of the Atlantis process user. The issue is fixed in version 0.45.0. An attacker who can cause Atlantis to process a crafted workspace value may cause filesystem operations to occur outside the intended workspace boundary, resulting in unintended directory creation, deletion, or reuse, integrity impact to writable local paths, or denial of service. This vulnerability has a CVSS score of 8.1.

RECOMMENDATION:

We recommend you to update Atlantis to version 0.45.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-64679 is a path traversal vulnerability with affected versions or code paths, Atlantis could create, use, or remove/recreate out-of-bounds directories with the privileges of the Atlantis process user, before Terraform rejec with affected versions, code path, deployment configuration, and filesystem permissions, this may result in unintended directory creation, deletion, or reuse, integrity impact to wri in Atlantis workspace handling that allows out-of-bounds directory deletion/creation. Affected versions are >= 0.19.8 and < 0.45.0, which did not consistently validate user-controlled workspace values before using them to construct local workspace paths. A crafted workspace value containing path traversal segments could cause Atlantis to resolve workspace paths outside the intended per-pull workspace directory, creating, using, or removing/recreating out-of-bounds directories with the privileges of the Atlantis process user. The issue is fixed in version 0.45.0. An attacker who can cause Atlantis to process a crafted workspace value may cause filesystem operations to occur outside the intended workspace boundary, resulting in unintended directory creation, deletion, or reuse, integrity impact to writable local paths, or denial of service. This vulnerability has a CVSS score of 8.1.

RECOMMENDATION:

We recommend you to update Atlantis to version 0.45.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu