CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-62725: compose < 2.40.2

CVE-2025-62725. EPSS 0.13701 (percentile 0.96398), scored 2026-10-06.

Affected technology

compose · < 2.40.2
docker

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Active user interaction

What an attacker can do

An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. Vendor/CNA’s CVSS 4.0 assessment (base score 8.9/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-22
CCR priority
3.4 /100 (P5)
EPSS
0.13701 · percentile 0.96406 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-62725.html