{"id":"CVE-2026-63328","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-63328","summary":"Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that…","details":"Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to install or run a malicious plugin to write the manifest and plugin binary to arbitrary user-writable paths, while plugins from the official Trivy plugin index are not affected. This issue is fixed in version 0.72.0.","published":"2026-08-18T16:18:12.387","modified":"2026-08-18T16:18:12.387","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/aquasecurity/trivy/commit/d4213d7735c74e57f06c02ccb39ebca67abc7959","label":"aquasecurity/trivy@d4213d7"},"references":[{"type":"WEB","url":"https://github.com/aquasecurity/trivy/commit/d4213d7735c74e57f06c02ccb39ebca67abc7959"},{"type":"WEB","url":"https://github.com/aquasecurity/trivy/releases/tag/v0.72.0"},{"type":"WEB","url":"https://github.com/aquasecurity/trivy/security/advisories/GHSA-8rc5-4fr6-64pw"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T16:18:12.387"}}