๐Ÿ” CVE Alert

CVE-2026-63328

UNKNOWN 0.0

Trivy: Path Traversal in Trivy Plugin Manager Allows Arbitrary File Write

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to install or run a malicious plugin to write the manifest and plugin binary to arbitrary user-writable paths, while plugins from the official Trivy plugin index are not affected. This issue is fixed in version 0.72.0.

CWE CWE-22
Vendor aquasecurity
Product trivy
Published Aug 18, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for aquasecurity trivy

Be the first to know when new unknown vulnerabilities affecting aquasecurity trivy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

aquasecurity / trivy
< 0.72.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/aquasecurity/trivy/security/advisories/GHSA-8rc5-4fr6-64pw github.com: https://github.com/aquasecurity/trivy/commit/d4213d7735c74e57f06c02ccb39ebca67abc7959 github.com: https://github.com/aquasecurity/trivy/releases/tag/v0.72.0