StackRadar

CVE-2025-26625

High

Advisory

Published 17 Oct 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
4 of 4
affected packages

Git LFS may write to arbitrary files via crafted symlinks

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
git-lfsdeb3.0.2-1, 3.0.2-1ubuntu0.2, 3.3.0-1+deb12u1, 3.4.0+3 more3.0.2-1ubuntu0.3+esm2, 3.4.1-1ubuntu0.3+esm211
git-lfsbitnami3.7.03.7.14
git-lfsrpm2.13.3-3.el8_60:3.4.1-6.el8_101
github.com/git-lfs/git-lfs/v3golangv0.0.0-20230726042507-d06d6e9efd78, v0.0.0-20240307195754-e237bb3a3646, v0.0.0-20250605231848-9e751d16509c, v0.0.0-20251016225643-b84b33847fe63.7.15
OSV records
BIT-git-lfs-2025-26625DEBIAN-CVE-2025-26625RHSA-2025:23745UBUNTU-CVE-2025-26625GO-2025-4038
Also known as
GHSA-6pvw-g552-53c5, RHSA-2026:0465, USN-7977-1

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
git-lfs@3.4.1-1ubuntu0.3
3.4.1-1ubuntu0.3+esm2

Open the chart page →

5,240
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
github.com/git-lfs/git-lfs/v3@v0.0.0-20251016225643-b84b33847fe6
3.7.1

Open the chart page →

4,556
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
bitnamisecure/gitdigest-pinned72ae5bd9715f
git-lfs@3.7.0
3.7.1

Open the chart page →

23,228
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
git-lfs@3.0.2-1ubuntu0.2
3.0.2-1ubuntu0.3+esm2

Open the chart page →

10,315
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

10,037
enbuildenbuildVerified publisher0.0.502 of 6See more

enbuild enbuild 0.0.50

2 of the 6 container images this version deploys carry CVE-2025-26625.

Open the chart page →

31,510
ilum-jupyterilumVerified publisher6.7.31 of 2See more

ilum-jupyter ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
bitnamisecure/gitdigest-pinned72ae5bd9715f
git-lfs@3.7.0
3.7.1

Open the chart page →

644
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
git-lfs@3.5.1
github.com/git-lfs/git-lfs/v3@v0.0.0-20240307195754-e237bb3a3646
no fix listed
3.7.1

Open the chart page →

7,387
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
git-lfs@3.4.0
github.com/git-lfs/git-lfs/v3@v0.0.0-20230726042507-d06d6e9efd78
no fix listed
3.7.1

Open the chart page →

9,102
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
git-lfs@3.4.0
github.com/git-lfs/git-lfs/v3@v0.0.0-20230726042507-d06d6e9efd78
no fix listed
3.7.1

Open the chart page →

9,102
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

7,300
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
git-lfs@3.5.1
github.com/git-lfs/git-lfs/v3@v0.0.0-20240307195754-e237bb3a3646
no fix listed
3.7.1

Open the chart page →

8,323
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
git-lfs@3.3.0-1+deb12u1
no fix listed

Open the chart page →

14,559
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
git-lfs@3.3.0-1+deb12u1
no fix listed

Open the chart page →

58,897
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
git-lfs@3.0.2-1
3.0.2-1ubuntu0.3+esm2

Open the chart page →

13,450
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
github.com/git-lfs/git-lfs/v3@v0.0.0-20250605231848-9e751d16509c
3.7.1

Open the chart page →

7,310
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

6,037
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
git-lfs@3.7.0
3.7.1

Open the chart page →

71,208
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

25,934
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2025-26625.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
git-lfs@2.13.3-3.el8_6
0:3.4.1-6.el8_10

Open the chart page →

16,047

Container images carrying it

18 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamisecure/git72ae5bd9715f
git-lfs@3.7.0
3.7.1
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
git-lfs@3.4.0
github.com/git-lfs/git-lfs/v3@v0.0.0-20230726042507-d06d6e9efd78
no fix listed
3.7.1
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2
2
1dev/server:11.9.0cd5b12fe5471
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
github.com/git-lfs/git-lfs/v3@v0.0.0-20251016225643-b84b33847fe6
3.7.1
1
bitnamilegacy/git:latest4b08d0c5af8d
git-lfs@3.7.0
3.7.1
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
git-lfs@3.5.1
github.com/git-lfs/git-lfs/v3@v0.0.0-20240307195754-e237bb3a3646
no fix listed
3.7.1
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
git-lfs@3.5.1
github.com/git-lfs/git-lfs/v3@v0.0.0-20240307195754-e237bb3a3646
no fix listed
3.7.1
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
git-lfs@3.3.0-1+deb12u1
no fix listed
1
openvino/model_server:2025.2.11e7cd1d70cc1
github.com/git-lfs/git-lfs/v3@v0.0.0-20250605231848-9e751d16509c
3.7.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
git-lfs@3.3.0-1+deb12u1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
git-lfs@3.0.2-1
3.0.2-1ubuntu0.3+esm2
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
git-lfs@3.4.1-1ubuntu0.3
3.4.1-1ubuntu0.3+esm2
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
git-lfs@3.0.2-1ubuntu0.2
3.0.2-1ubuntu0.3+esm2
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
git-lfs@2.13.3-3.el8_6
0:3.4.1-6.el8_10
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
git-lfs@3.7.0
3.7.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
git-lfs@3.7.0
3.7.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.