PT-2026-50251 · Aqua Security · Trivy

·

CVE-2026-55092

·

Published

2026-06-17

·

Updated

2026-09-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Trivy versions prior to 0.71.1
Description Trivy improperly trusts the org.opencontainers.image.title annotation in an OCI artifact manifest, using it as the destination filename when downloading content without proper validation or sanitization. This path traversal flaw allows an attacker to supply a crafted annotation that resolves to a path outside the intended destination. If Trivy is tricked into fetching an attacker-controlled artifact, it can result in writing layer content to an arbitrary location on the host filesystem, potentially enabling local privilege escalation, persistence, or service disruption.
Recommendations Update to version 0.71.1.

Exploit

Fix

LPE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55092
GHSA-MCJ4-MPHF-J9FF
GO-2026-6294
OPENSUSE-SU-2026:11162-1
OPENSUSE-SU-2026:21249-1
OPENSUSE-SU-2026:21761-1

Affected Products

Trivy