THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8394-6f8r-whxg (medium) — Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

[GHSA] GHSA-8394-6f8r-whxg (medium) — Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

medgithub_advisoriesPublished 2026-08-17

GHSA-8394-6f8r-whxg Severity: medium CVE: CVE-2026-45099

Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

### Summary

Terragrunt is vulnerable to an arbitrary file deletion flaw when downloading external modules. If a remote module contains a maliciously crafted `.terragrunt-module-manifest` file, Terragrunt can be tricked into deleting files anywhere on the local filesystem th

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8394-6f8r-whxg