VYPR

Osv Scalibr

by Google

Source repositories

CVEs (3)

  • CVE-2026-102252MedSep 29, 2026
    risk 0.38cvss —epss 0.00

    A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient…

  • CVE-2025-5981MedJun 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.

  • CVE-2025-13425LowNov 20, 2025
    risk 0.05cvss —epss 0.00

    A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (denial of service) in OSV-SCALIBR.