CVE-2026-26189 | aquasecurity trivy-action up to 0.33.x os command injection (GHSA-9p44-j4g5-cfx5)
A vulnerability classified as critical was found in aquasecurity trivy-action up to 0.33.x. Affected by this vulnerability is an unknown functionality. The manipulation results in os command injection.
This vulnerability is reported as CVE-2026-26189. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.