GHSA-2hcm-q3f4-fjgw

Suggest an improvement
Source
https://github.com/advisories/GHSA-2hcm-q3f4-fjgw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-2hcm-q3f4-fjgw/GHSA-2hcm-q3f4-fjgw.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-2hcm-q3f4-fjgw
Aliases
Published
2025-06-18T09:30:31Z
Modified
2025-07-28T20:30:16.633492Z
Severity
  • 5.7 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal
Details

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.

Database specific
{
    "cwe_ids": [
        "CWE-427"
    ],
    "nvd_published_at": "2025-06-18T09:15:47Z",
    "github_reviewed_at": "2025-06-18T19:45:44Z",
    "github_reviewed": true,
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/google/osv-scalibr

Package

Name
github.com/google/osv-scalibr
View open source insights on deps.dev
Purl
pkg:golang/github.com/google/osv-scalibr

Affected ranges

Type
SEMVER
Events
Introduced
0.1.3
Fixed
0.2.1