#cve-2025-62725

[ follow ]
#docker-compose
fromTheregister
3 days ago
Information security

Docker Compose vulnerability opens door to host-level writes

Docker Compose's OCI artifact handling had a path traversal vulnerability (CVE-2025-62725) allowing arbitrary host file writes; upgrade to Compose v2.40.
fromTechzine Global
2 days ago
Information security

Docker fixes serious vulnerabilities in Compose and Desktop Installer

Docker fixed two high-risk vulnerabilities: a Docker Compose path-annotation flaw allowing host file writes and a Docker Desktop Windows installer DLL hijack.
[ Load more ]