THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8rc5-4fr6-64pw (medium) — Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

[GHSA] GHSA-8rc5-4fr6-64pw (medium) — Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

highgithub_advisoriesPublished 2026-08-18

GHSA-8rc5-4fr6-64pw Severity: medium CVE: CVE-2026-63328

Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write

## Summary

Trivy's plugin manager does not fully validate metadata from a plugin's manifest before using it to construct filesystem paths under the plugin root (`~/.trivy/plugins`). A crafted plugin can cause Trivy to write its files (the manifest and the downloaded

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8rc5-4fr6-64pw