tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This caused reports to render values that should have been masked as "(sensitive)" instead. This issue is fixed in v1.26.1. No known workarounds are available.

Project Subscriptions

Vendors Products
Tfplan2md Subscribe
Tfplan2md Subscribe
Tfplan2md Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Tfplan2md
Tfplan2md tfplan2md
CPEs cpe:2.3:a:tfplan2md:tfplan2md:*:*:*:*:*:*:*:*
Vendors & Products Tfplan2md
Tfplan2md tfplan2md
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 25 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Oocx
Oocx tfplan2md
Vendors & Products Oocx
Oocx tfplan2md

Wed, 25 Feb 2026 04:15:00 +0000

Type Values Removed Values Added
Description tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This caused reports to render values that should have been masked as "(sensitive)" instead. This issue is fixed in v1.26.1. No known workarounds are available.
Title tfplan2md has Sensitive Value Exposure in Generated Reports
Weaknesses CWE-212
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-25T21:21:08.940Z

Reserved: 2026-02-20T22:02:30.029Z

Link: CVE-2026-27640

cve-icon Vulnrichment

Updated: 2026-02-25T21:20:30.126Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-25T04:16:04.450

Modified: 2026-02-27T18:45:02.947

Link: CVE-2026-27640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-25T11:34:42Z

Weaknesses