Infracost has two medium-severity vulnerabilities affecting its configuration-template processing and Terraform Cloud/Enterprise integrations. Both vulnerabilities have a CVSS v4 score of 5.9 and affect Infracost versions prior to 0.10.45. Exploitation can result in arbitrary file disclosure from the CI runner or exposure of Terraform Cloud/Enterprise and registry credentials when untrusted Terraform configuration is processed.
CVE-2026-71493 (CVSS v4 5.9): A medium-severity path traversal and symlink-following vulnerability in the Infracost config-template parser allows attacker-controlled repository content to bypass path restrictions. By placing an intermediate directory symlink in a repository and using template functions such as `readFile`, an attacker can cause Infracost to read files outside the repository checkout. The contents can then be surfaced through generated configuration, dashboard output, or pull-request comments. Depending on the CI configuration, this could expose repository secrets and other sensitive files accessible to the Infracost process. Affected versions are up to 0.10.44.[/subscribe_to_unlock_form]
Infracost has two medium-severity vulnerabilities affecting its configuration-template processing and Terraform Cloud/Enterprise integrations. Both vulnerabilities have a CVSS v4 score of 5.9 and affect Infracost versions prior to 0.10.45. Exploitation can result in arbitrary file disclosure from the CI runner or exposure of Terraform Cloud/Enterprise and registry credentials when untrusted Terraform configuration is processed.
CVE-2026-71493 (CVSS v4 5.9): A medium-severity path traversal and symlink-following vulnerability in the Infracost config-template parser allows attacker-controlled repository content to bypass path restrictions. By placing an intermediate directory symlink in a repository and using template functions such as `readFile`, an attacker can cause Infracost to read files outside the repository checkout. The contents can then be surfaced through generated configuration, dashboard output, or pull-request comments. Depending on the CI configuration, this could expose repository secrets and other sensitive files accessible to the Infracost process. Affected versions are up to 0.10.44.[emaillocker id="1283"]
CVE-2026-71494 (CVSS v4 5.9): A medium-severity sensitive-information disclosure vulnerability in the Infracost Terraform Cloud/Enterprise and registry integrations allows an attacker-controlled hostname from Terraform configuration to receive a configured secret token. Because the destination hostname was not validated against the trusted endpoint, malicious Terraform can potentially cause Terraform Cloud/Enterprise or registry credentials to be disclosed. Exploitation depends on the CI workflow providing the relevant token while processing untrusted Terraform configuration, particularly configurations such as `pull_request_target` or same-repository pull requests. Affected versions are prior to 0.10.45.
We recommend you to update infracost to version 0.10.45.
The following reports contain further technical details:
[/emaillocker]