OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal
Moderate severity
GitHub Reviewed
Published
Jun 18, 2025
to the GitHub Advisory Database
•
Updated Jun 18, 2025
Package
Affected versions
>= 0.1.3, < 0.2.1
Patched versions
0.2.1
Description
Published by the National Vulnerability Database
Jun 18, 2025
Published to the GitHub Advisory Database
Jun 18, 2025
Reviewed
Jun 18, 2025
Last updated
Jun 18, 2025
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.
References