CVE-2025-2180
Checkov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code Execution
Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
8.0th percentile
Discovered by
Third party
Vendor-published field
Published
Aug 13, 2025
Assigned by palo_alto
Description
An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.
Weakness: CWE-502
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Cloud | Cloud Security | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Checkov by Prisma Cloud
Credit
Palo Alto Networks thanks Bryan Eastes for discovering and reporting this issue.
Vendor remediation
Version Minor Version Suggested Solution Checkov by Prisma Cloud 3.2 3.2.0 through 3.2.414 Upgrade to 3.2.415 or later.