{"id":"GHSA-9p44-j4g5-cfx5","summary":"Trivy Action has a script injection via sourced env file in composite action","details":"Command Injection in aquasecurity/trivy-action via Unsanitized Environment Variable Export\n\n\nA command injection vulnerability exists in `aquasecurity/trivy-action` due to improper handling of action inputs when exporting environment variables. The action writes `export VAR=\u003cinput\u003e` lines to `trivy_envs.txt` based on user-supplied inputs and subsequently sources this file in `entrypoint.sh`.\n\nBecause input values are written without appropriate shell escaping, attacker-controlled input containing shell metacharacters (e.g., `$(...)`, backticks, or other command substitution syntax) may be evaluated during the sourcing process. This can result in arbitrary command execution within the GitHub Actions runner context.\n\n**Severity:**\n\nModerate\n\nCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N\n\nCWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)\n\n**Impact:**\n\nSuccessful exploitation may lead to arbitrary command execution in the CI runner environment.\n\n\n**Affected Versions:**\n\n* Versions \u003e= 0.31.0 and \u003c= 0.33.1\n* Introduced in commit `7aca5ac`\n\n**Affected Conditions:**\n\nThe vulnerability is exploitable when a consuming workflow passes attacker-controlled data into any action input that is written to `trivy_envs.txt`. Access to user input is required by the malicious actor.\n\nA representative exploitation pattern involves incorporating untrusted pull request metadata into an action parameter. For example:\n\n```yaml\n- uses: aquasecurity/trivy-action@0.33.1\n  with:\n    output: \"trivy-${{ github.event.pull_request.title }}.sarif\"\n```\n\nIf the pull request title contains shell syntax, it may be executed when the generated environment file is sourced.\n\n**Not Affected:**\n\n* Workflows that do not pass attacker-controlled data into `trivy-action` inputs\n* Workflows that upgrade to a patched version that properly escapes shell values or eliminates the `source ./trivy_envs.txt` pattern\n* Workflows where user input is not accessible.\n\n**Call Sites:**\n\n* `action.yaml:188` — `set_env_var_if_provided` writes unescaped `export` lines\n* `entrypoint.sh:9` — sources `./trivy_envs.txt`","aliases":["CVE-2026-26189"],"modified":"2026-09-15T06:32:47.001518109Z","published":"2026-02-18T15:24:43Z","database_specific":{"cwe_ids":["CWE-78"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-18T15:24:43Z","nvd_published_at":"2026-02-19T20:25:42Z"},"references":[{"type":"WEB","url":"https://github.com/aquasecurity/trivy-action/security/advisories/GHSA-9p44-j4g5-cfx5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26189"},{"type":"WEB","url":"https://github.com/aquasecurity/trivy-action/commit/7aca5acc9500b463826cc47a47a65ad7d404b045"},{"type":"WEB","url":"https://github.com/aquasecurity/trivy-action/commit/bc61dc55704e2d5704760f3cdab0d09acf16e4ca"},{"type":"PACKAGE","url":"https://github.com/aquasecurity/trivy-action"}],"affected":[{"package":{"name":"aquasecurity/trivy-action","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.31.0"},{"fixed":"0.34.0"}]},{"type":"GIT","repo":"https://github.com/aquasecurity/trivy-action","events":[{"introduced":"76071ef0d7ec797419534a183b498b4d6366cf37"},{"fixed":"c1824fd6edce30d7ab345a9989de00bbd46ef284"}]}],"versions":["v0.33.1","0.33.1","v0.33.0","0.33.0","v0.32.0","0.32.0","v0.31.0","0.31.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-9p44-j4g5-cfx5/GHSA-9p44-j4g5-cfx5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N"}]}