CVE-2025-62725LOWCVSS 8.92025
CVE-2025-62725 [HIGH] CVE-2025-62725: docker-compose - Docker Compose trusts the path information embedded in remote OCI compose artifa...
Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platfor
debian