THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-26w5-6g95-gj28 (high) — Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

[GHSA] GHSA-26w5-6g95-gj28 (high) — Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

medgithub_advisoriesPublished 2026-08-21

GHSA-26w5-6g95-gj28 Severity: high CVE: CVE-2026-64679

Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation

### Summary Atlantis versions `>= 0.19.8` and `< 0.45.0` did not consistently validate user-controlled `workspace` values before using them to construct local workspace paths.

A crafted workspace value containing path traversal segments coul

Indicators of compromise

Original source: https://github.com/advisories/GHSA-26w5-6g95-gj28