Executive brief
Checkov by Prisma Cloud is an infrastructure-as-code (IaC) scanning tool used by organizations to validate cloud configurations and detect misconfigurations. The vulnerability allows arbitrary code execution when Checkov processes an attacker-controlled configuration file in a scanned directory, potentially compromising systems that scan untrusted or shared code repositories.
Technical details
This is a code execution vulnerability stemming from untrusted control sphere inclusion (CWE-829). The root cause is Checkov's automatic loading of configuration files from the scanned directory without proper validation. The attack vector is local with low complexity—an attacker places a malicious configuration file in a directory that Checkov will scan, and when invoked without explicit trusted configuration, the tool auto-loads and executes the attacker's code. User interaction is passive (simply running the scan). The attack requires no authentication or special privileges. A patch is available in version 3.2.532 and later; users should upgrade immediately or avoid scanning untrusted content until patched.
Affected products
- Palo Alto Networks Checkov by Prisma Cloud 3.2.0 through 3.2.531
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fix available in version 3.2.532 and later