Intel

AIKIDO-2025-10591

checkov is vulnerable to Unsafe Deserialization

Unsafe DeserializationCVE-2025-2180 Published Aug 28, 2025

90

Critical Risk

This Affects:

pythoncheckov
0.0.0 - 3.2.414
Fixed in 3.2.415
Are you affected? Scan for Free

TL;DR

An unsafe deserialization vulnerability in checkov allows an attacker to execute arbitrary code when scanning a malformed Terraform file. This could allow an attacker to achieve elevated privileges where checkov is running, e.g. in the CI/CD pipeline or a developer's machine, allowing an attacker to potentially exfiltrate secrets of the environment.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

checkov is vulnerable to Unsafe Deserialization in versions 0.0.0 - 3.2.414.

How to fix this

Upgrade checkov to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform