THREAT OPS › Threat News › [GHSA] GHSA-8rc5-4fr6-64pw (medium) — Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
[GHSA] GHSA-8rc5-4fr6-64pw (medium) — Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
GHSA-8rc5-4fr6-64pw Severity: medium CVE: CVE-2026-63328
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
## Summary
Trivy's plugin manager does not fully validate metadata from a plugin's manifest before using it to construct filesystem paths under the plugin root (`~/.trivy/plugins`). A crafted plugin can cause Trivy to write its files (the manifest and the downloaded
Indicators of compromise
- CVE-2026-63328cve
- https://trivy.dev/docs/latest/guide/plugin/url
Original source: https://github.com/advisories/GHSA-8rc5-4fr6-64pw