CVE-2025-62725HIGHCVSS 8.9fixed in 2.40.22025-10-27
CVE-2025-62725 [HIGH] CWE-22 CVE-2025-62725: Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer in
Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any
nvd