{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/docker-compose/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2025-62725"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Docker Compose"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Docker"],"content_html":"\u003cp\u003eMicrosoft has disclosed CVE-2025-62725, a security vulnerability affecting Docker Compose. The flaw resides in how the tool processes OCI artifact layer annotations. An attacker capable of crafting a malicious OCI artifact can leverage this path traversal vulnerability to access or manipulate files on the host system where Docker Compose is executed. This vulnerability poses a significant risk to development and build environments that ingest OCI artifacts from untrusted or compromised sources. Defenders should prioritize patching Docker Compose versions to the remediated release provided by the vendor, as this allows arbitrary file write or read access depending on the specific implementation context of the build process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized file system access on the host, potentially leading to arbitrary code execution if an attacker can overwrite configuration files or binary paths used by the system. This impacts any environment utilizing Docker Compose for container orchestration or CI/CD pipelines, increasing the risk of supply chain compromise or container breakout.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Docker Compose to the latest version immediately to patch CVE-2025-62725.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD pipelines to ensure OCI artifacts are pulled only from trusted and verified registries.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual file system access patterns originating from the Docker Compose process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-08T09:31:54Z","date_published":"2026-08-08T09:31:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-docker-compose-path-traversal/","summary":"CVE-2025-62725 is a critical path traversal vulnerability in Docker Compose, allowing for unauthorized file system access or manipulation during the processing of malicious OCI artifact layer annotations.","title":"Path Traversal Vulnerability in Docker Compose OCI Artifact Processing","url":"https://feed.craftedsignal.io/briefs/2026-08-docker-compose-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Docker Compose","version":"https://jsonfeed.org/version/1.1"}