PT-2026-50251 · Aqua Security · Trivy
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Trivy versions prior to 0.71.1
Description
Trivy improperly trusts the
org.opencontainers.image.title annotation in an OCI artifact manifest, using it as the destination filename when downloading content without proper validation or sanitization. This path traversal flaw allows an attacker to supply a crafted annotation that resolves to a path outside the intended destination. If Trivy is tricked into fetching an attacker-controlled artifact, it can result in writing layer content to an arbitrary location on the host filesystem, potentially enabling local privilege escalation, persistence, or service disruption.Recommendations
Update to version 0.71.1.
Exploit
Fix
LPE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trivy