Path Traversal Vulnerability in Trivy Security Scanner by Aqua Security
CVE-2026-63328
6.8MEDIUM
What is CVE-2026-63328?
Trivy, a security scanner by Aqua Security, has a vulnerability in earlier versions where plugin manifest metadata can be exploited. Specifically, prior to version 0.72.0, the plugin manager did not properly confine paths constructed under ~/.trivy/plugins, which allows attackers to potentially install malicious plugins that could write arbitrary files to user-writable paths. This vulnerability does not affect plugins from the official Trivy plugin index. Users are advised to upgrade to version 0.72.0 or later to mitigate this risk.
Affected Version(s)
trivy < 0.72.0
