MEDIUM GitHub
CVE-2026-45099
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
### Summary
Terragrunt is vulnerable to an arbitrary file deletion flaw when downloading external modules. If a remote module contains a maliciously crafted `.terragrunt-module-manifest` file, Terragrunt can be tricked into deleting files anywhere on the local filesystem that the Terragrunt process has access to.
### Impact
This vulnerability impacts users who download and run untrusted or compromised OpenTofu/Terraform modules. The file deletion occurs during the module download and initiali
Affected Products
- go/github.com/gruntwork-io/terragrunt < 1.0.4
References
- https://github.com/advisories/GHSA-8394-6f8r-whxg
- https://github.com/gruntwork-io/terragrunt/security/advisories/GHSA-8394-6f8r-whxg
- https://github.com/gruntwork-io/terragrunt/releases/tag/v1.0.4
- https://github.com/advisories/GHSA-8394-6f8r-whxg
This medium severity vulnerability was published on 2026-08-17 via GitHub. Affected: go/github.com/gruntwork-io/terragrunt < 1.0.4.
vulnfeed aggregates 11030 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.