THREAT OPS › Threat News › [GHSA] GHSA-mcj4-mphf-j9ff (high) — Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
[GHSA] GHSA-mcj4-mphf-j9ff (high) — Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
GHSA-mcj4-mphf-j9ff Severity: high CVE: CVE-2026-55092
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
## Summary
When Trivy downloads an OCI artifact, it uses the `org.opencontainers.image.title` annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact
Indicators of compromise
- CVE-2026-55092cve
Original source: https://github.com/advisories/GHSA-mcj4-mphf-j9ff