GHSA-h626-pv66-hhm7
GitHub Security Advisory
Terraform allows arbitrary file write during the `init` operation
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously crafted Terraform configuration. This vulnerability is fixed in Terraform 1.5.7.
Affected Packages
Go
github.com/hashicorp/terraform
Affected versions:
1.0.8
(fixed in 1.5.7)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.