CVE-2026-63328 is a medium-severity vulnerability in Trivy, a security scanner. The vulnerability allows an attacker to write plugin manifest and binary data to arbitrary user-writable paths. This issue was fixed in version 0.72.0. The vulnerability is caused by the use of plugin manifest metadata to construct paths under ~/.trivy/plugins without confining plugin names to that root. This allows an attacke [truncated]
Known exploitedAquasecurityCVE published 2026-03-26
CVE-2026-33634 is a CISA Known Exploited Vulnerability affecting Aqua Security Trivy. The available official records describe it as an embedded malicious code vulnerability and note that it may represent a supply-chain compromise that can affect multiple products and environments. Because CISA added it to the KEV catalog, defenders should treat it as an active risk requiring prompt mitigation based on ven [truncated]