Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-55092— Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts

Quick assessment

Affected
aquasecurity trivy
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Aqua Security Trivy是Aqua Security公司开源的一款全面且多功能的安全扫描仪。 Aqua Security Trivy 0.71.1之前版本存在路径遍历漏洞,该漏洞源于在下载OCI工件时未对org.opencontainers.image.title注释进行验证,可能导致攻击者通过特制注释将层内容写入主机文件系统的任意位置。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.44% · P36

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
aquasecurity trivy < 0.71.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55092

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts
Source: CVE Program / CVE List V5
Vulnerability Description
Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a path outside the intended destination, causing Trivy to write the layer content to an arbitrary location on the host filesystem. This vulnerability is fixed in 0.71.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
Aqua Security Trivy 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Aqua Security Trivy是Aqua Security公司开源的一款全面且多功能的安全扫描仪。 Aqua Security Trivy 0.71.1之前版本存在路径遍历漏洞,该漏洞源于在下载OCI工件时未对org.opencontainers.image.title注释进行验证,可能导致攻击者通过特制注释将层内容写入主机文件系统的任意位置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
aquasecurity trivy < 0.71.1 -

II. Public POCs for CVE-2026-55092

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55092

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-55092 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-55092

No comments yet


Leave a comment