CVE-2026-63328 | Aquasecurity Trivy up to 0.71.x Plugin Manifest pkg/plugin/manager.go path traversal
A vulnerability marked as critical has been reported in Aquasecurity Trivy up to 0.71.x. Affected by this vulnerability is an unknown functionality of the file pkg/plugin/manager.go of the component Plugin Manifest. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-63328. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More