CVE-2026-26189Patch(aquasec / trivy_action)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch aquasec trivy_action systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31.0 through 0.33.1 due to improper handling of action inputs when exporting environment variables. The action writes `export VAR=<input>` lines to `trivy_envs.txt` based on user-supplied inputs and subsequently sources this file in `entrypoint.sh`. Because input values are written without appropriate shell escaping, attacker-controlled input containing shell metacharacters (e.g., `$(...)`, backticks, or other command substitution syntax) may be evaluated during the sourcing process. This can result in arbitrary command execution within the GitHub Actions runner context. Version 0.34.0 contains a patch for this issue. The vulnerability is exploitable when a consuming workflow passes attacker-controlled data into any action input that is written to `trivy_envs.txt`. Access to user input is required by the malicious actor. Workflows that do not pass attacker-controlled data into `trivy-action` inputs, workflows that upgrade to a patched version that properly escapes shell values or eliminates the `source ./trivy_envs.txt` pattern, and workflows where user input is not accessible are not affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trivy_action

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
trivy_action

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-27: 103-27
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Hephaestvs@Vulcanux_
    Patch

    csirt_it: ‼ Trivy: Attacco Multistadio alla Supply Chain CI/CD e Iniezione di Codice Malevolo - #CanisterWorm (CVE-2026-26189 &amp; CVE-2026-33634) Rischio: 🔴 🔗 https://www.acn.gov.it/portale/w/attacco-multistadio-alla-supply-chain-ci/cd-e-iniezione-di-codice-malevolo ⚠ Mitigazioni e procedure di hardening disponibili https://t.co/IhCBDjtkLT

    Post summary

    The post announces a multi‑stage CI/CD supply chain attack involving CVE-2026-26189 and CVE-2026-33634, citing mitigation and hardening procedures, but offers no PoC, exploit code, or evidence of active exploitation.

    0000055
    605 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaquasectrivy_action---

Explore more