Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18630 | OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal |
Github GHSA |
GHSA-2hcm-q3f4-fjgw | OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal |
Thu, 07 Aug 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google osv-scalibr |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:google:osv-scalibr:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Google
Google osv-scalibr |
|
| Metrics |
cvssV3_1
|
Wed, 18 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Jun 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images. | |
| Title | Arbitrary File write in OSV-SCALIBR | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-06-18T13:42:49.567Z
Reserved: 2025-06-10T12:31:04.353Z
Link: CVE-2025-5981
Updated: 2025-06-18T13:42:43.144Z
Status : Analyzed
Published: 2025-06-18T09:15:47.660
Modified: 2025-08-07T15:34:04.500
Link: CVE-2025-5981
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA