PT-2026-60918 · Aqua Security · Trivy

CVE-2026-63328

·

Published

2026-07-17

·

Updated

2026-09-04

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Trivy versions prior to 0.72.0
Description A path traversal flaw exists in the plugin manager where plugin manifest metadata is used to construct paths under ~/.trivy/plugins without properly confining plugin names to that root. An attacker can exploit this by persuading a user to install or run a malicious plugin with a crafted plugin.yaml file, enabling the writing of the manifest and plugin binary to arbitrary user-writable paths and the overwriting of system files. This issue occurs within the pkg/plugin/manager.go file. Plugins sourced from the official Trivy plugin index are not affected.
Recommendations Update to version 0.72.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63328
GHSA-8RC5-4FR6-64PW
GO-2026-6250
OPENSUSE-SU-2026:21761-1

Affected Products

Trivy