CVE-2026-63328
Trivy: Path Traversal in Trivy Plugin Manager Allows Arbitrary File Write
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to install or run a malicious plugin to write the manifest and plugin binary to arbitrary user-writable paths, while plugins from the official Trivy plugin index are not affected. This issue is fixed in version 0.72.0.
| CWE | CWE-22 |
| Vendor | aquasecurity |
| Product | trivy |
| Published | Aug 18, 2026 |
| Last Updated | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for aquasecurity trivy
Be the first to know when new unknown vulnerabilities affecting aquasecurity trivy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
aquasecurity / trivy
< 0.72.0