CVE-2026-55092
Last modified
CVE-2026-55092 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a path outside the intended destination, causing Trivy to write the layer content to an arbitrary location on the host filesystem. This vulnerability is fixed in 0.71.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Aquasec | Trivy | < 0.71.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-55092?
How severe is CVE-2026-55092?
How do I fix CVE-2026-55092?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55087Etherpad is a real-time collaborative editor. From 2.1.0 unt…6.1
- CVE-2026-55088Etherpad is a real-time collaborative editor. From 2.6.0 unt…6.8
- CVE-2026-55089Etherpad is a real-time collaborative editor. From 2.1.0 unt…9.9
- CVE-2026-5509An authenticated command injection vulnerability exists in t…7.2
- CVE-2026-55090Etherpad is a real-time collaborative editor. Prior to 3.3.0…5.3
- CVE-2026-55091flat-to-nested converts a hierarchy from a flat representati…7.5
- CVE-2026-55093Tract is a tiny, no-nonsense, self-contained TensorFlow and …6.1
- CVE-2026-55095OpenProject is open-source, web-based project management sof…5.3
- CVE-2026-55099icalendar is an RFC 5545 compatible parser and generator of …7.5
- CVE-2026-5510The GiveWP – Donation Plugin and Fundraising Platform plugin…6.4
- CVE-2026-55100hashi-vault-js is a Node.js module for interacting with the …8.7
- CVE-2026-55102hashi-vault-js is a Node.js module for interacting with the …5.8
Are you affected by CVE-2026-55092?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
