THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mcj4-mphf-j9ff (high) — Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

[GHSA] GHSA-mcj4-mphf-j9ff (high) — Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

medgithub_advisoriesPublished 2026-08-25

GHSA-mcj4-mphf-j9ff Severity: high CVE: CVE-2026-55092

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

## Summary

When Trivy downloads an OCI artifact, it uses the `org.opencontainers.image.title` annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mcj4-mphf-j9ff