PT-2026-21856 · Tfplan2Md · Tfplan2Md

Oocx

·

Published

2026-02-25

·

Updated

2026-03-04

·

CVE-2026-27640

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions tfplan2md versions prior to 1.26.1
Description tfplan2md is software used to convert Terraform plan JSON files into Markdown reports. Versions of the software prior to 1.26.1 had a flaw where sensitive values that should have been masked as "(sensitive)" were instead rendered in plain text in several rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This resulted in potential exposure of sensitive data.
Recommendations Update to version 1.26.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27640
GHSA-5J8R-G94Q-2F39

Affected Products

Tfplan2Md