CVE-2026-71493 | Infracost up to 0.10.44 Template Parser parser.go readFile/pathExists/isDir/matchPaths path traversal

SecurityVulns

A vulnerability classified as problematic was found in Infracost up to 0.10.44. This issue affects the function readFile/pathExists/isDir/matchPaths of the file internal/config/template/parser.go of the component Template Parser. Executing a manipulation can lead to path traversal.

This vulnerability is handled as CVE-2026-71493. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More