icon

We found results for “

CVE-2025-53945

Good to know:

icon

Date: July 18, 2025

apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Incorrect Default Permissions

CWE-276

Top Fix

icon

Upgrade Version

Upgrade to version chainguard.dev/apko - v0.29.5

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): HIGH
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us