CVE-2025-2180

Checkov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code Execution

Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
8.0th percentile
Discovered by
Third party
Published by the vendor
Published
Aug 13, 2025
Assigned by palo_alto

Description

An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.

Weakness: CWE-502

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Palo Alto Networks · Checkov by Prisma Cloud

Credit

Palo Alto Networks thanks Bryan Eastes for discovering and reporting this issue.

Vendor remediation

Version Minor Version Suggested Solution Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.414 Upgrade to 3.2.415 or later.