Intel

AIKIDO-2025-10591

checkov is vulnerable to Unsafe Deserialization

Unsafe DeserializationCVE-2025-2180 Published Aug 28, 2025

90

Critical Risk

This Affects:

pythoncheckov
0.0.0 - 3.2.414
Fixed in 3.2.415
Are you affected? Scan for Free

TL;DR

An unsafe deserialization vulnerability in checkov allows an attacker to execute arbitrary code when scanning a malformed Terraform file. This could allow an attacker to achieve elevated privileges where checkov is running, e.g. in the CI/CD pipeline or a developer's machine, allowing an attacker to potentially exfiltrate secrets of the environment.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

checkov is vulnerable to Unsafe Deserialization in versions 0.0.0 - 3.2.414.

How to fix this

Upgrade checkov to the patch version.