CVE Explorer
CVE-2025-62725
Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev en
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"compose","vendor":"docker","versions":[{"status":"affected","version":"< 2.40.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4a1244748c9bc44f37e401c2de216835523ff6c104153219994140b1fe402049 · sha256:8179446b00017d7d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.9,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"ACTIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4a1244748c9bc44f37e401c2de216835523ff6c104153219994140b1fe402049 · sha256:8179446b00017d7d… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4a1244748c9bc44f37e401c2de216835523ff6c104153219994140b1fe402049 · sha256:8179446b00017d7d… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/docker/compose/commit/69bcb962bfb2ea53b41aa925333d356b577d6176","tags":["x_refsource_MISC"],"url":"https://github.com/docker/compose/commit/69bcb962bfb2ea53b41aa925333d356b577d6176"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4a1244748c9bc44f37e401c2de216835523ff6c104153219994140b1fe402049 · sha256:8179446b00017d7d… · /containers/cna/references/1
{"name":"https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4a1244748c9bc44f37e401c2de216835523ff6c104153219994140b1fe402049 · sha256:8179446b00017d7d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.