CVE-2026-55092: Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts
Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a path outside the intended destination, causing Trivy to write the layer content to an arbitrary location on the host filesystem. This vulnerability is fixed in 0.71.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trivyto a version that resolves this vulnerability.Fixed in 0.71.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55092?
The severity of CVE-2026-55092 is rated at 55.
How do I fix CVE-2026-55092?
To fix CVE-2026-55092, upgrade Trivy to version 0.71.1 or later.
What type of vulnerability is CVE-2026-55092?
CVE-2026-55092 is a path traversal vulnerability.
What could an attacker do with CVE-2026-55092?
An attacker could exploit CVE-2026-55092 to place files in arbitrary directories on the system.
Which versions of Trivy are affected by CVE-2026-55092?
Versions of Trivy prior to 0.71.1 are affected by CVE-2026-55092.