Palo Alto Networks Checkov by Prisma Cloud Unsafe Deserialization Vulnerability Allows Arbitrary Code Execution

Vulnerability

A vulnerability allowing unsafe deserialization has been identified in Palo Alto Networks Checkov by Prisma Cloud. This issue allows an authenticated user to execute arbitrary code as a non-administrative user. The vulnerability arises when Checkov scans a malicious Terraform file from untrusted sources. It affects Checkov versions 3.2.0 prior to 3.2.415.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code.

Remediation

Users are advised to upgrade to Checkov version 3.2.415 or later. Additionally, it is recommended not to run Checkov on Terraform files from untrusted sources or pull requests.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.4
remediation
0.0
relevance
0.3
threat
0.0
urgency
5.7
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.