Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64679— Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation

Quick assessment

Affected
runatlantis atlantis
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Atlantis 是一个自托管的 Go 语言应用程序,通过 Webhooks 监听来自 Terraform 的拉取请求事件。在版本 0.19.8 至 0.45.0 之间,Atlantis 未能一致地验证通过已接受的仓库级 配置或经身份验证的 接口传入的用户可控工作区(workspace)参数。这些未经验证的安全漏洞可能导致遍历段(如 )突破预期的每个拉取请求专用工作区目录限制,在 Terraform 拒绝无效工作区名称之前,使克隆准备或其他工作目录处理路径对越界的目录执行 、 或其他文件系统操作。 此漏洞可能导致

CVSS 8.1 · High EPSS 0.38% · P31

Affected Version Matrix 1

VendorProduct Version RangeStatus
runatlantis atlantis >= 0.19.8, < 0.45.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-64679

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation
Source: CVE Program / CVE List V5
Vulnerability Description
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or authenticated /api/plan input before joining them into local workspace paths. Traversal segments can escape the intended per-pull workspace directory and cause clone preparation or other working-directory code paths to call os.RemoveAll, os.MkdirAll, or related filesystem operations on out-of-bounds directories before Terraform rejects the invalid workspace name. This can create, delete, or reuse writable paths with the privileges of the Atlantis process, causing integrity loss or denial of service. This issue is fixed in version 0.45.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
runatlantis atlantis >= 0.19.8, < 0.45.0 -

II. Public POCs for CVE-2026-64679

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8025 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-64679

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64679 (1)

Vendor Advisories for CVE-2026-64679 (1)

Vendor Pages for CVE-2026-64679 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-64679

No comments yet


Leave a comment