Trivy ecosystem supply chain briefly compromised
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for help- Published
- Mar 23, 2026
- Updated
- Jun 17, 2026
- EPSS
- 1.7% · 76th percentile▼ 57
- CWE
- CWE-506
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
68
This week
Don’t wait for the next maintenance window.
- CVSS
- 37 / 40 · 9.4 / 10
- CISA KEV
- 30 / 30 · Listed
- EPSS
- 1 / 30 · 1.7%
CISA SSVC decision
- Exploitation
- active
- Automatable
- no
- Technical impact
- total
Vulnrichment: CISA's decision-tree inputs.
CNA vs NVD score
- NVD
- —
- CNA · GitHub_M
- 9.4
- NVD has not scored this yet; the score shown is the CNA’s.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.
Actively exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on Mar 26, 2026. That signals real attacks, not theory.
Remediation deadline for government agencies: Apr 9, 2026.
Affected systems
| Vendor | Product | CPE |
|---|---|---|
| aquasec | setup-trivy | cpe:2.3:a:aquasec:setup-trivy |
| aquasec | trivy | cpe:2.3:a:aquasec:trivy |
| aquasec | trivy action | cpe:2.3:a:aquasec:trivy_action |
| litellm | litellm | cpe:2.3:a:litellm:litellm |
| telnyx | telnyx | cpe:2.3:a:telnyx:telnyx |
Affected versions
NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.
- aquasec setup-trivybefore 0.2.6
- aquasec trivy0.69.4
- aquasec trivy actionbefore 0.35.0
- litellm litellm1.82.7
- litellm litellm1.82.8
- telnyx telnyx4.87.1
- telnyx telnyx4.87.2
Versions reported by the vendor
Affected version ranges reported by the assigning authority (GitHub_M). Independent of NVD's CPE analysis and usually ahead of it.
aquasecurity setup-trivy
- < 0.2.6affected
aquasecurity trivy
- = 0.69.4affected
aquasecurity trivy-action
- < 0.35.0affected
BerriAI LiteLLM
- >= 1.82.7, <= 1.82.8affected
team-telnyx telnyx
- >= 4.87.1, <= 4.87.2affected
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| GitHub Actions | aquasecurity/setup-trivy | before 0.2.6 | 0.2.6 |
| GitHub Actions | aquasecurity/setup-trivy | before 0.2.6 | 0.2.6 |
| GitHub Actions | aquasecurity/trivy-action | before 0.35.0 | 0.35.0 |
| GitHub Actions | aquasecurity/trivy-action | before 0.35.0 | 0.35.0 |
| Go | github.com/aquasecurity/trivy | from 0.69.4 | — |
| Go | github.com/aquasecurity/trivy | all versions | — |
| openSUSE:Leap 15.6 | govulncheck-vulndb | before 0.0.20260402T184258-150000.1.158.1 | 0.0.20260402T184258-150000.1.158.1 |
| PyPI | telnyx | from 4.87.1 · up to and including 4.87.2 | — |
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| GitHub Actions:aquasecurity/setup-trivy | 0.2.6 | Package registry (OSV) |
| GitHub Actions:aquasecurity/trivy-action | 0.35.0 | Package registry (OSV) |
| opensuse:govulncheck-vulndb | 0.0.20260402T184258-150000.1.158.1 · openSUSE:Leap 15.6 | Package registry (OSV) |
Exploit status
Weaponized
A ready exploit tool or active in-the-wild use is known for this vulnerability. This should be your top priority.
Evidence
- Proof-of-concept repository on GitHub ×5
Noroxi does not host or link to exploit code. Metasploit module names and Nuclei template ids are shown (names, not code); Exploit-DB entries and PoC repositories are given as counts only.
| Source | Kind | Date |
|---|---|---|
| Proof-of-concept repository on GitHub | stars:12 | 2026-03-25 |
| Proof-of-concept repository on GitHub | stars:0 | 2026-03-30 |
| Proof-of-concept repository on GitHub | stars:0 | 2026-03-31 |
| Proof-of-concept repository on GitHub | stars:0 | 2026-07-15 |
| Proof-of-concept repository on GitHub | stars:0 | 2026-09-21 |
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
- Published
- First PoC+1 d
- CISA KEV+2 d
- TodaySep 30, 2026+191 d
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
No credits in the CNA record.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
Attack conditions
- Anyone who can reach it over the internet can trigger it.
- A low-privileged account is enough.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- Integrity
- Availability
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- X
Weakness class (CWE)
CWE-506 · Embedded Malicious CodeCVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvd-secondary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
Attack patterns (CAPEC)
ATT&CK techniques
- Data Obfuscation: SteganographyT1001.002
- Obfuscated Files or Information: SteganographyT1027.003
- Obfuscated Files or Information: Compile After DeliveryT1027.004
- Obfuscated Files or Information: Embedded PayloadsT1027.009
- Supply Chain Compromise: Compromise Software Dependencies and Development ToolsT1195.001
- Supply Chain Compromise: Compromise Software Supply ChainT1195.002
- Signed Binary Proxy Execution: Compiled HTML FileT1218.001
- Template InjectionT1221
Change log
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →
References
- docs.litellm.ai/blog/security-update-march-2026
- futuresearch.ai/blog/litellm-pypi-supply-chain-attack
- github.com/BerriAI/litellm/issues/24518
- github.com/aquasecurity/trivy/discussions/10425
- github.com/pypa/advisory-database/tree/main/vulns/litellm/PYSEC-2026-2.yaml
- github.com/team-telnyx/telnyx-python/security/advisories/GHSA-955r-262c-33jc
- inspector.pypi.io/project/litellm/1.82.7/packages/79/5f/b6998d42c6ccd32d36e12661f2734602e72a576d52a51f4245aef0b20b4d/litellm-1.82.7-py3-none-any.whl/litellm/proxy/proxy_server.py#line.130
- inspector.pypi.io/project/litellm/1.82.8/packages/f6/2c/731b614e6cee0bca1e010a36fd381fba69ee836fe3cb6753ba23ef2b9601/litellm-1.82.8.tar.gz/litellm-1.82.8/litellm_init.pth#line.1
- www.wiz.io/blog/teampcp-attack-kics-github-action
- github.com/BerriAI/litellm/issues/24518#issuecomment-4127436387
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33634
- www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/
Vendor advisories and official records. Exploit/PoC links are deliberately left out.