CVE-2026-63328 | Aquasecurity Trivy up to 0.71.x Plugin Manifest pkg/plugin/manager.go path traversal

SecurityVulns

A vulnerability marked as critical has been reported in Aquasecurity Trivy up to 0.71.x. Affected by this vulnerability is an unknown functionality of the file pkg/plugin/manager.go of the component Plugin Manifest. The manipulation leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-63328. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More