tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This caused reports to render values that should have been masked as "(sensitive)" instead. This issue is fixed in v1.26.1. No known workarounds are available.
History

Wed, 25 Feb 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Oocx
Oocx tfplan2md
Vendors & Products Oocx
Oocx tfplan2md

Wed, 25 Feb 2026 04:15:00 +0000

Type Values Removed Values Added
Description tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchical sensitivity detection. This caused reports to render values that should have been masked as "(sensitive)" instead. This issue is fixed in v1.26.1. No known workarounds are available.
Title tfplan2md has Sensitive Value Exposure in Generated Reports
Weaknesses CWE-212
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-25T03:52:26.615Z

Reserved: 2026-02-20T22:02:30.029Z

Link: CVE-2026-27640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-25T04:16:04.450

Modified: 2026-02-25T14:15:29.980

Link: CVE-2026-27640

cve-icon Redhat

No data.