blob: 8020f0b4901b12d07274ff4b28ef49106d488860 [file] [log] [blame]
id: GO-2025-4077
modules:
- module: github.com/docker/compose
vulnerable_at: 1.25.2
- module: github.com/docker/compose/v2
versions:
- fixed: 2.40.2
vulnerable_at: 2.40.1
summary: Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations in github.com/docker/compose
cves:
- CVE-2025-62725
ghsas:
- GHSA-gv8h-7v7w-r22q
references:
- advisory: https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-62725
- fix: https://github.com/docker/compose/commit/69bcb962bfb2ea53b41aa925333d356b577d6176
source:
id: GHSA-gv8h-7v7w-r22q
created: 2025-10-28T17:25:51.997298885Z
review_status: UNREVIEWED