https://seclists.org/oss-sec/2026/q1/361: Trivy github actions po compromised, infostealer added
Published Mar 21, 2026
·Updated
Affected Software
1 affected component
github/aquasecurity/trivy-action
Frequently Asked Questions
1
What is the severity of CVE-2026-12345?
The severity of CVE-2026-12345 is critical due to the potential for widespread compromise of systems using the Trivy GitHub Action.
2
How do I fix CVE-2026-12345?
To fix CVE-2026-12345, immediately revoke any compromised credentials and update to the latest secure version of the trivy-action.
3
What are the risks associated with CVE-2026-12345?
The risks associated with CVE-2026-12345 include unauthorized access, data exfiltration, and the potential infection of systems with malware.
4
Who is affected by CVE-2026-12345?
Any user or organization utilizing the compromised trivy-action in their GitHub workflows is affected by CVE-2026-12345.
5
What mitigation strategies can be employed for CVE-2026-12345?
Mitigation strategies for CVE-2026-12345 include using dependency scanning, monitoring for suspicious activity, and restricting GitHub Action access to critical repositories.