CVE-2025-48385
HighAdvisory
Published 8 Jul 2025In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.6
- base score, highest
- EPSS
- 0.009
- 59th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 166
- of 17,781 indexed, latest versions
- Container images
- 160
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Git alllows arbitrary file writes via bundle-uri parameter injection
Carried by container images the latest versions of 166 of 17,781 indexed charts deploy, on 160 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gitdeb | 1:2.39.2-1.1, 1:2.39.5-0+deb12u1, 1:2.39.5-0+deb12u2, 1:2.43.0-1ubuntu7.2 | 1:2.39.5-0+deb12u3, 1:2.43.0-1ubuntu7.3 | 123 |
| gitapk | 2.40.4-r0, 2.43.0-r0, 2.43.4-r0, 2.43.5-r0+6 more | 2.43.7-r0, 2.45.4-r0, 2.47.3-r0, 2.49.1-r0+1 more | 36 |
| gitbitnami | 2.50.0-1 | 2.50.1 | 1 |
- OSV records
- ALPINE-CVE-2025-48385BIT-git-2025-48385DEBIAN-CVE-2025-48385UBUNTU-CVE-2025-48385
- Also known as
- GHSA-m98c-vgpc-9655, USN-7626-1
Charts affected
166 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| spacecapybara-chartspacecapy | 1.0.49 | 1 of 2See more | 11,888 |
| stakefishstakefish | 0.1.0 | 1 of 8See more | 20,223 |
| ssv-nodestakewise | 2.2.0 | 1 of 2See more | 6,779 |
| verbasubstratusVerified publisher | 0.4.0 | 1 of 1See more | 13,390 |
| cronjobt3n | 0.1.0 | 1 of 1See more | 11,199 |
| helm-testtest-helm-artifacthubVerified publisher | 1.0.0 | 1 of 2See more | 11,648 |
| chatqnatest-opea | 1.0.0 | 1 of 11See more | 39,090 |
| codegentest-opea | 1.0.0 | 2 of 5See more | 28,814 |
| codetranstest-opea | 1.0.0 | 2 of 5See more | 28,385 |
| docsumtest-opea | 1.0.0 | 2 of 5See more | 28,858 |
| node-redthl-chartsVerified publisher | 0.1.0 | 1 of 1See more | 2,806 |
| harbor-scanner-trivytrivy-operator | 0.31.2 | 1 of 1See more | 2,477 |
| tfy-distributortruefoundryVerified publisher | 0.0.1 | 1 of 4See more | 17,323 |
| jupyterhubuninettsigma2 | 1.6.0 | 1 of 5See more | 8,607 |
| demo-backendv2flyVerified publisher | 0.0.3 | 1 of 1See more | 14,358 |
| marge-botwiremindVerified publisher | 1.4.4 | 1 of 1See more | 5,542 |
Container images carrying it
160 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | bf5983d754d7 | git | 2.45.4-r0 | 1 |
| ghcr.io/ | fbba58ddb1a6 | git | 1:2.39.5-0+deb12u3 | 1 |
| ghcr.io/ | 7dc0ee57b628 | git | 1:2.39.5-0+deb12u3 | 1 |
| public.ecr.aws/ | b1493760c716 | git | 1:2.39.5-0+deb12u3 | 1 |
| public.ecr.aws/ | 5cd62142d6ed | git | 1:2.39.5-0+deb12u3 | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | git | 1:2.39.5-0+deb12u3 | 1 |
| public.ecr.aws/ | f74851ce31f5 | git | 1:2.39.5-0+deb12u3 | 1 |
| quay.io/ | 95b5cf7ba6fe | git | 1:2.43.0-1ubuntu7.3 | 1 |
| quay.io/ | e0d9b93dbf2b | git | 1:2.39.5-0+deb12u3 | 1 |
| registry.k8s.io/ | fd9722fd02e3 | git | 1:2.39.5-0+deb12u3 | 1 |