PatchSiren

runatlantis CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH runatlantis CVE published 2026-08-21

CVE-2026-64679

Atlantis, a self-hosted golang application, is vulnerable to a path traversal attack. This occurs due to inconsistent validation of user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or authenticated /api/plan input. The vulnerability allows an attacker to create, delete, or reuse writable paths with the privileges of the Atlantis process, potentially l [truncated]