CVE-2026-26189: Trivy Action has a script injection via sourced env file in composite action

Published Feb 18, 2026
·
Updated

Command Injection in aquasecurity/trivy-action via Unsanitized Environment Variable Export

A command injection vulnerability exists in aquasecurity/trivy-action due to improper handling of action inputs when exporting environment variables. The action writes export VAR=<input> lines to trivyenvs.txt based on user-supplied inputs and subsequently sources this file in entrypoint.sh.

Because input values are written without appropriate shell escaping, attacker-controlled input containing shell metacharacters (e.g., $(...), backticks, or other command substitution syntax) may be evaluated during the sourcing process. This can result in arbitrary command execution within the GitHub Actions runner context.

Severity:

Moderate

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)

Impact:

Successful exploitation may lead to arbitrary command execution in the CI runner environment.

Affected Versions:

Versions >= 0.31.0 and <= 0.33.1 Introduced in commit 7aca5ac

Affected Conditions:

The vulnerability is exploitable when a consuming workflow passes attacker-controlled data into any action input that is written to trivyenvs.txt. Access to user input is required by the malicious actor.

A representative exploitation pattern involves incorporating untrusted pull request metadata into an action parameter. For example:

yaml - uses: aquasecurity/trivy-action@0.33.1 with: output: "trivy-${{ github.event.pullrequest.title }}.sarif"

If the pull request title contains shell syntax, it may be executed when the generated environment file is sourced.

Not Affected:

Workflows that do not pass attacker-controlled data into trivy-action inputs Workflows that upgrade to a patched version that properly escapes shell values or eliminates the source ./trivyenvs.txt pattern Workflows where user input is not accessible.

Call Sites:

action.yaml:188 — setenvvarifprovided writes unescaped export lines entrypoint.sh:9 — sources ./trivyenvs.txt

Other sources

Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in aquasecurity/trivy-action versions 0.31.0 through 0.33.1 due to improper handling of action inputs when exporting environment variables. The action writes export VAR=<input> lines to trivyenvs.txt based on user-supplied inputs and subsequently sources this file in entrypoint.sh. Because input values are written without appropriate shell escaping, attacker-controlled input containing shell metacharacters (e.g., $(...), backticks, or other command substitution syntax) may be evaluated during the sourcing process. This can result in arbitrary command execution within the GitHub Actions runner context. Version 0.34.0 contains a patch for this issue. The vulnerability is exploitable when a consuming workflow passes attacker-controlled data into any action input that is written to trivyenvs.txt. Access to user input is required by the malicious actor. Workflows that do not pass attacker-controlled data into trivy-action inputs, workflows that upgrade to a patched version that properly escapes shell values or eliminates the source ./trivyenvs.txt pattern, and workflows where user input is not accessible are not affected.

NVD

Affected Software

2 affected componentsFixes available
actions/aquasecurity/trivy-action>=0.31.0<0.34.0
0.34.0
aquasec Trivy Action>=0.31.0<0.34.1

Event History

Feb 18, 2026
Advisory Published
via GitHub·03:24 PM
Data Sourced
via GitHub·03:24 PM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:25 PM
RemedyAffected Software
Jan 23, 58126
Event
via FIRST·08:45 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-26189?

CVE-2026-26189 is classified as a high severity vulnerability due to the potential for command injection.

2

How do I fix CVE-2026-26189?

To fix CVE-2026-26189, upgrade aquasecurity/trivy-action to version 0.35.0 or later.

3

What software is affected by CVE-2026-26189?

CVE-2026-26189 affects aquasecurity/trivy-action versions from 0.31.0 to 0.34.0.

4

What kind of vulnerability is CVE-2026-26189?

CVE-2026-26189 is a command injection vulnerability caused by improper handling of action inputs.

5

How does CVE-2026-26189 exploit environment variables?

CVE-2026-26189 exploits unsanitized inputs by writing potentially harmful commands into exported environment variables.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203