Home

Description

tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This caused reports to render values that should have been masked as "(sensitive)" instead. This issue is fixed in v1.26.1. No known workarounds are available.

PUBLISHED Reserved 2026-02-20 | Published 2026-02-25 | Updated 2026-02-25 | Assigner GitHub_M




HIGH: 8.5CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H

Problem types

CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer

Product status

< 1.26.1
affected

References

github.com/...lan2md/security/advisories/GHSA-5j8r-g94q-2f39

github.com/oocx/tfplan2md/releases/tag/v1.26.1

cve.org (CVE-2026-27640)

nvd.nist.gov (CVE-2026-27640)

Download JSON