Path traversal in trivy - CVE-2026-63328

 

Path traversal in trivy - CVE-2026-63328

Published: July 1, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU136054
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63328
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to write arbitrary files outside the intended plugin directory.

The vulnerability exists due to path traversal in the plugin manager when installing an attacker-controlled plugin. A local user can provide a crafted plugin manifest to write arbitrary files outside the intended plugin directory.

User interaction is required to install the crafted plugin, and exploitation is limited to locations writable by the user running Trivy.


Affected software

trivy

How to mitigate CVE-2026-63328

Install security update from vendor's website.

trivy - update to 0.72.0

External References

Related Security Bulletins