CVE-2025-5981

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:osv-scalibr:*:*:*:*:*:go:*:*

History

No history.

Information

Published : 2025-06-18 09:15

Updated : 2025-08-07 15:34


NVD link : CVE-2025-5981

Mitre link : CVE-2025-5981

CVE.ORG link : CVE-2025-5981


JSON object : View

Products Affected

google

  • osv-scalibr
CWE
CWE-427

Uncontrolled Search Path Element

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')