GHSA-mcj4-mphf-j9ff: Path Traversal

Published Aug 25, 2026
·
Updated

Summary

When Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a path outside the intended destination, causing Trivy to write the layer content to an arbitrary location on the host filesystem.

Affected configurations

Exploitation requires the attacker to direct Trivy at an attacker-controlled OCI artifact via one of the following inputs:

| Input | Used for | | --- | --- | | --db-repository flag, TRIVYDBREPOSITORY environment variable, or db.repository in trivy.yaml | Vulnerability database | | --java-db-repository flag, TRIVYJAVADBREPOSITORY environment variable, or db.java-repository in trivy.yaml | Java vulnerability database | | --checks-bundle-repository flag (and the deprecated --policy-bundle-repository alias), TRIVYCHECKSBUNDLEREPOSITORY environment variable, or misconfiguration.checks-bundle-repository in trivy.yaml | Misconfiguration checks bundle | | Repository argument to trivy module install <REPO> | WASM module installation |

Realistic scenarios in which an attacker may influence these inputs include a copy-pasted command or documentation snippet pointing to an untrusted mirror, or a third-party mirror that turns out to be hostile.

Trivy's default configuration, which downloads these artifacts from Aqua-operated repositories, is not affected. The risk applies only when one of the inputs above is overridden to download a different artifact.

Impact

An attacker who satisfies the conditions above can overwrite or create arbitrary files on the host filesystem within the privilege boundary of the user running Trivy. The vulnerability does not grant any privileges beyond what that user already has.

The practical impact depends on the deployment. In environments where the running user can overwrite files such as SSH authorizedkeys, shell startup files, cron entries, or binaries on PATH, the file write may be leveraged to achieve code execution as that user. In more restricted deployments, the impact is bounded to the user's writable scope but may still allow tampering with scan results, build artifacts, or other files consumed by subsequent steps in the same pipeline.

Patches

Fixed in Trivy 0.71.1. Users should upgrade to that release or later.

Workarounds

If upgrading is not immediately possible, do not download Trivy artifacts (vulnerability database, Java database, misconfiguration checks bundle, modules, etc.) from OCI repositories you do not operate or trust.

Credits

Reported by @ikkebr.

Affected Software

1 affected componentFixes available
go/github.com/aquasecurity/trivy<0.71.1
0.71.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/aquasecurity/trivy to a version that resolves this vulnerability.

    Fixed in 0.71.1
  2. Upgrade

    Upgrade Trivy to a version that resolves this vulnerability.

    Fixed in 0.71.1
  3. Compensating control

    If upgrading is not immediately possible, do not download Trivy artifacts (vulnerability database, Java database, misconfiguration checks bundle, modules, etc.) from OCI repositories you do not operate or trust.

Event History

Aug 25, 2026
Advisory Published
via GitHub·05:33 PM
Data Sourced
via GitHub·05:33 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203