CVE-2025-5981

Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:osv-scalibr:*:*:*:*:*:go:*:*

History

07 Aug 2025, 15:34

Type Values Removed Values Added
References () https://github.com/google/osv-scalibr/commit/2444419b1818c2d6917fc3394c947fb3276e9d59 - () https://github.com/google/osv-scalibr/commit/2444419b1818c2d6917fc3394c947fb3276e9d59 - Patch
References () https://github.com/google/osv-scalibr/releases/tag/v0.1.8 - () https://github.com/google/osv-scalibr/releases/tag/v0.1.8 - Release Notes
First Time Google
Google osv-scalibr
Summary
  • (es) Escritura arbitraria de archivos como usuario OSV-SCALIBR en el sistema host mediante una vulnerabilidad de path traversal al usar la función unpack() de OSV-SCALIBR para imágenes de contenedor. En particular, al usar la opción CLI --remote-image en imágenes de contenedor no confiables.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-22
CPE cpe:2.3:a:google:osv-scalibr:*:*:*:*:*:go:*:*

18 Jun 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-18 09:15

Updated : 2025-08-07 15:34


NVD link : CVE-2025-5981

Mitre link : CVE-2025-5981

CVE.ORG link : CVE-2025-5981


JSON object : View

Products Affected

google

  • osv-scalibr
CWE
CWE-427

Uncontrolled Search Path Element

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')