CVE-2025-2180 MEDIUM

CVE-2025-2180: Checkov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code Execution

Vendor Palo Alto Networks
Product Checkov by Prisma Cloud
Weakness CWE-502 · Unsafe deserialization
Published August 13, 2025
Last update August 13, 2025

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/AU:N/R:U/V:D/RE:M/U:Amber

What the vulnerability does

01Description

An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.

Key dates

02Disclosure timeline

August 13, 2025 CVE published
August 13, 2025 Record updated

Related vulnerabilities

04Related CVE