Vulnerability Details CVE-2025-5981
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIBR's unpack() function for container images. Particularly, when using the CLI flag --remote-image on untrusted container images.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.5%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2025-5981
-
cpe:2.3:a:google:osv-scalibr:0.1.3
-
cpe:2.3:a:google:osv-scalibr:0.1.4
-
cpe:2.3:a:google:osv-scalibr:0.1.5
-
cpe:2.3:a:google:osv-scalibr:0.1.6
-
cpe:2.3:a:google:osv-scalibr:0.1.7