Arbitrary File write in OSV-SCALIBR
Vulnerability Description
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5981
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Anthony Weems of Google's Cloud Vulnerability Research team
- Simon Scannell of Google's Cloud Vulnerability Research team
- Stefan Schiller of Google's Cloud Vulnerability Research team