CVE-2026-33634 | aquasecurity setup-trivy/trivy-action/trivy up to 0.2.5 malicious code (GHSA-69fq-xp46-6x23)
A vulnerability marked as critical has been reported in aquasecurity setup-trivy, trivy-action and trivy up to 0.2.5. Impacted is an unknown function. The manipulation leads to embedded malicious code.
This vulnerability is listed as CVE-2026-33634. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to upgrade the affected component.