References https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q https://nvd.nist.gov/vuln/detail/CVE-2025-62725 https://securityonline.info/docker-compose-path-traversal-cve-2025-62725-allows-arbitrary-file-overwrite-via-oci-artifacts/ https://www.imperva.com/blog/cve-2025-62725-from-docker-compose-ps-to-system-compromise/ https://github.com/runtipi/runtipi/security/advisories/GHSA-mwg8-x997-cqw6 https://www.ampcuscyber.com/shadowopsintel/malicious-oci-artifacts-enable-system-compromise-via-docker-compose/ https://access.redhat.com/security/cve/cve-2025-62725
Related VulnerabilitiesPoCCVE-2022-39258: Mailcow Dockerized Swagger UI - Cross-Site ScriptingPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication Bypass金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞PoCdockerrun-aws-json-exposure: AWS Elastic Beanstalk Dockerrun.aws.json - ExposurePoCCVE-2024-23055: Plone Docker - Host Header Injection金和OA BudgetDecomposeEdit.aspx SQL注入漏洞金和OA AjaxForSetDecompose.ashx SQL注入漏洞金和OA AjaxForCenterBudgetDecompose.ashx SQL注入漏洞dpanel /api/app/compose/get-from-uri 文件读取漏洞(CVE-2025-53363)docker-registry-api-unauth: docker registry api 未经批准docker-registry: Docker Registry ListingDocker Desktop Engine API 未授权访问漏洞