THREAT OPS › Threat News › [GHSA] GHSA-26w5-6g95-gj28 (high) — Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
[GHSA] GHSA-26w5-6g95-gj28 (high) — Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
GHSA-26w5-6g95-gj28 Severity: high CVE: CVE-2026-64679
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
### Summary Atlantis versions `>= 0.19.8` and `< 0.45.0` did not consistently validate user-controlled `workspace` values before using them to construct local workspace paths.
A crafted workspace value containing path traversal segments coul
Indicators of compromise
- CVE-2026-64679cve
Original source: https://github.com/advisories/GHSA-26w5-6g95-gj28