CVE-2026-45099: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in gruntwork-io terragrunt
CVE-2026-45099 is a path traversal vulnerability in gruntwork-io Terragrunt versions prior to 1.0.4. The issue arises from Terragrunt trusting paths decoded from a downloaded module's .terragrunt-module-manifest during a cleanup operation. A malicious or compromised external module can exploit this to delete files outside the intended module cache, potentially removing local source code or configuration and disrupting CI/CD pipelines. This vulnerability is fixed in version 1.0.4.
AI Analysis
Technical Summary
Terragrunt versions before 1.0.4 improperly limit pathnames during the cleanup of downloaded module manifests. Specifically, the fileManifest.Clean() function in internal/util/file.go trusts paths from the .terragrunt-module-manifest without sufficient validation. This allows an attacker controlling a module to specify absolute or traversal paths that cause deletion of files outside the module cache accessible to the Terragrunt process. The vulnerability is a deletion-only primitive, meaning it cannot modify or create files but can remove critical local files, impacting local source code or configuration and disrupting automated pipelines. The issue is resolved in Terragrunt version 1.0.4.
Potential Impact
An attacker who can supply or compromise an external module can cause Terragrunt to delete arbitrary files accessible to its process on the local filesystem. This can lead to loss of local source code or configuration files and disrupt continuous integration and deployment workflows. There is no indication of remote code execution or privilege escalation. The impact is limited to file deletion within the permissions of the Terragrunt process.
Mitigation Recommendations
Upgrade Terragrunt to version 1.0.4 or later, where this path traversal and unauthorized file deletion vulnerability is fixed. No other mitigations are indicated or required.
CVE-2026-45099: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in gruntwork-io terragrunt
Description
CVE-2026-45099 is a path traversal vulnerability in gruntwork-io Terragrunt versions prior to 1.0.4. The issue arises from Terragrunt trusting paths decoded from a downloaded module's .terragrunt-module-manifest during a cleanup operation. A malicious or compromised external module can exploit this to delete files outside the intended module cache, potentially removing local source code or configuration and disrupting CI/CD pipelines. This vulnerability is fixed in version 1.0.4.
CVSS v4.0
Score 6.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Terragrunt versions before 1.0.4 improperly limit pathnames during the cleanup of downloaded module manifests. Specifically, the fileManifest.Clean() function in internal/util/file.go trusts paths from the .terragrunt-module-manifest without sufficient validation. This allows an attacker controlling a module to specify absolute or traversal paths that cause deletion of files outside the module cache accessible to the Terragrunt process. The vulnerability is a deletion-only primitive, meaning it cannot modify or create files but can remove critical local files, impacting local source code or configuration and disrupting automated pipelines. The issue is resolved in Terragrunt version 1.0.4.
Potential Impact
An attacker who can supply or compromise an external module can cause Terragrunt to delete arbitrary files accessible to its process on the local filesystem. This can lead to loss of local source code or configuration files and disrupt continuous integration and deployment workflows. There is no indication of remote code execution or privilege escalation. The impact is limited to file deletion within the permissions of the Terragrunt process.
Mitigation Recommendations
Upgrade Terragrunt to version 1.0.4 or later, where this path traversal and unauthorized file deletion vulnerability is fixed. No other mitigations are indicated or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8394-6f8r-whxg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-45099"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a838cdcbf8831d539b67f46
Added to database: 08/17/2026, 22:36:12 UTC
Last enriched: 09/12/2026, 00:02:59 UTC
Last updated: 10/02/2026, 02:46:04 UTC
Views: 41
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.