StackRadar

CVE-2025-54798

Low

Advisory

Published 6 Aug 2025In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
2.5
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
169
of 17,781 indexed, latest versions
Container images
165
deployed by those charts
Fix available
1 of 1
affected package

tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

Carried by container images the latest versions of 169 of 17,781 indexed charts deploy, on 165 images.

Affected packageAffected versionsFixed inImages
tmpnpm0.0.23, 0.0.28, 0.0.29, 0.0.30+4 more0.2.4165
OSV records
GHSA-52f5-9888-hmc6

Charts affected

169 by stars
ChartLatestAffected imagesRadar Score
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tmp@0.0.33
0.2.4

Open the chart page →

4,455
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
tmp@0.0.33
0.2.4
sysnet4admin/colosseum-prm:log5802bfcd7fed
tmp@0.0.33
0.2.4

Open the chart page →

26,996
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
tmp@0.0.23
0.2.4

Open the chart page →

4,069
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
tmp@0.2.1
0.2.4

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
tmp@0.0.33
0.2.4

Open the chart page →

4,083
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
tmp@0.2.3
0.2.4

Open the chart page →

2,759
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
tmp@0.0.33
0.2.4

Open the chart page →

29,901
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
tmp@0.0.33
0.2.4

Open the chart page →

2,580
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
tmp@0.0.33
0.2.4

Open the chart page →

77,758
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
tmp@0.0.33
0.2.4

Open the chart page →

25,456
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
tmp@0.0.33
0.2.4

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
tmp@0.0.33
0.2.4

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
tmp@0.0.33
0.2.4

Open the chart page →

5,141
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
tmp@0.2.1
0.2.4

Open the chart page →

9,146
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
tmp@0.2.3
0.2.4

Open the chart page →

14,559
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
tmp@0.0.33
0.2.4

Open the chart page →

5,488
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
tmp@0.0.28
0.2.4

Open the chart page →

5,209
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
tmp@0.2.1
0.2.4

Open the chart page →

13,852
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
tmp@0.2.1
0.2.4

Open the chart page →

3,042
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
tmp@0.0.33
0.2.4

Open the chart page →

4,551
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
tmp@0.2.1
0.2.4

Open the chart page →

2,862
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
tmp@0.0.33
0.2.4

Open the chart page →

11,174
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
tmp@0.2.1
0.2.4

Open the chart page →

27,096
blockscoutethereum-helm-chartsVerified publisher0.2.31 of 2See more

blockscout ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
blockscout/blockscout:5.1.5c365a8f2dc12
tmp@0.0.33
0.2.4

Open the chart page →

1,928
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
tmp@0.0.33
0.2.4

Open the chart page →

2,522
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
tmp@0.0.33
0.2.4

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
tmp@0.0.33
0.2.4

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
tmp@0.0.33
0.2.4

Open the chart page →

4,756
smeejasfanzynoodle0.0.11 of 1See more

smeejas fanzynoodle 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
fanzynoodle/smeejas:0.0.15f9916c1a287
tmp@0.2.1
0.2.4

Open the chart page →

4,127
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
tmp@0.2.1
0.2.4

Open the chart page →

2,172
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
tmp@0.0.33
0.2.4

Open the chart page →

5,941
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
tmp@0.0.33
0.2.4

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
tmp@0.0.33
0.2.4

Open the chart page →

2,973
Governify-Bluejaygovernify0.1.04 of 12See more

Governify-Bluejay governify 0.1.0

4 of the 12 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
tmp@0.0.33
0.2.4
governify/registry:v3.4.0d3f37f4f8168
tmp@0.2.1
0.2.4
governify/render:v2.2.0daeca1ce28e6
tmp@0.0.33
0.2.4
governify/reporter:v2.2.038595913458f
tmp@0.0.33
0.2.4

Open the chart page →

22,512
Governify-Falcongovernify0.1.05 of 10See more

Governify-Falcon governify 0.1.0

5 of the 10 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
tmp@0.0.33
0.2.4
governify/collector-dynamic:v1.3.06d3d1a5b46a9
tmp@0.2.1
0.2.4
governify/registry:v3.4.0d3f37f4f8168
tmp@0.2.1
0.2.4
governify/render:v2.2.0daeca1ce28e6
tmp@0.0.33
0.2.4
governify/reporter:v2.2.038595913458f
tmp@0.0.33
0.2.4

Open the chart page →

24,319
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
tmp@0.2.3
0.2.4

Open the chart page →

49,025
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
tmp@0.2.1
0.2.4

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
tmp@0.2.1
0.2.4

Open the chart page →

2,682
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
tmp@0.0.33
0.2.4

Open the chart page →

2,064
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
tmp@0.1.0
0.2.4
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
tmp@0.0.33
0.2.4
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
tmp@0.1.0
0.2.4
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
tmp@0.1.0
0.2.4

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
tmp@0.2.1
0.2.4

Open the chart page →

8,213
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
tmp@0.0.33
0.2.4

Open the chart page →

25,017
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
tmp@0.0.33
0.2.4

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
tmp@0.0.29
0.2.4

Open the chart page →

57,669
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
tmp@0.0.33
0.2.4

Open the chart page →

4,944
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
tmp@0.0.33
0.2.4

Open the chart page →

7,232
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
tmp@0.2.3
0.2.4

Open the chart page →

5,826
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
tmp@0.0.28
0.2.4

Open the chart page →

4,614
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
tmp@0.0.33
0.2.4

Open the chart page →

6,454
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-54798.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
tmp@0.2.1
0.2.4

Open the chart page →

2,166

Container images carrying it

165 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fanzynoodle/smeejas:0.0.15f9916c1a287
tmp@0.2.1
0.2.4
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
tmp@0.0.33
0.2.4
1
getferdi/ferdi-server:1.3.26e620b85afaa
tmp@0.0.33
0.2.4
1
globalping/globalping-probe:latest8acbd23009fd
tmp@0.0.33
0.2.4
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
tmp@0.2.1
0.2.4
1
gristlabs/grist:0.7.96e71b1914a7e
tmp@0.2.1
0.2.4
1
halkeye/irslackd:latest7638bfba70b0
tmp@0.0.33
0.2.4
1
heywood8/redisinsight:2.28.00bc9ab313d37
tmp@0.0.33
0.2.4
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
tmp@0.0.33
0.2.4
1
hugohg34/server:0.0.2503e5d8960ff
tmp@0.2.1
0.2.4
1
ianw/quickchart:v1.7.1dc49dd460c37
tmp@0.0.33
0.2.4
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
tmp@0.0.30
0.2.4
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
tmp@0.0.33
0.2.4
1
ibmcom/microclimate-portal:latested5505e5c7ec
tmp@0.0.29
0.2.4
1
jayfong/yapi:1.10.2163e5d621910
tmp@0.0.33
0.2.4
1
konradkleine/docker-registry-frontend:v2181aad54ee64
tmp@0.0.23
0.2.4
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
tmp@0.2.1
0.2.4
1
kubebb/component-store:latestfd8ecbd73213
tmp@0.2.1
0.2.4
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
tmp@0.2.1
0.2.4
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
tmp@0.2.1
0.2.4
1
kubevious/backend:1.2.22d9ba6eb46b6
tmp@0.2.1
0.2.4
1
kubevious/parser:1.2.299ae7a5168c2
tmp@0.2.1
0.2.4
1
kyleslugg/klusterview:latestba8c36dfdfbd
tmp@0.2.1
0.2.4
1
kyso/kyso-front:lateste52595c5c16f
tmp@0.0.33
0.2.4
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tmp@0.2.3
0.2.4
1
library/ghost:4.37.0767230c0f263
tmp@0.0.33
0.2.4
1
library/ghost:5.79.083f7bf209844
tmp@0.0.33
0.2.4
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
tmp@0.0.33
0.2.4
1
library/kibana:8.18.004c0fc150f3a
tmp@0.0.33
0.2.4
1
linuxserver/cloud9:latest45c5fe102ff3
tmp@0.0.33
0.2.4
1
linuxserver/codimd:latestb801bbcf6386
tmp@0.0.33
0.2.4
1
lissy93/dashy:2.0.51991f7be5ed0
tmp@0.0.33
0.2.4
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
tmp@0.0.33
0.2.4
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
tmp@0.2.1
0.2.4
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
tmp@0.0.33
0.2.4
1
minddocdev/hubot:0.1.96c60b11a4fa7
tmp@0.0.33
0.2.4
1
mishtinetwork/operator:latestbb3fe67a5f7c
tmp@0.0.33
0.2.4
1
misskey/misskey:12.110.1e08b7c478093
tmp@0.2.1
0.2.4
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
tmp@0.0.33
0.2.4
1
mozilla/sentencecollector:2.0.91da6ff5c4895
tmp@0.0.33
0.2.4
1
n8nio/n8n:1.86.08b39ed5a2de9
tmp@0.2.3
0.2.4
1
n8nio/n8n:0.212.0a9195bc499a3
tmp@0.2.1
0.2.4
1
n8nio/n8n:1.33.1dd171d45102a
tmp@0.0.33
0.2.4
1
nocodb/nocodb:0.258.06779a4ddedf2
tmp@0.0.33
0.2.4
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
tmp@0.2.1
0.2.4
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
tmp@0.0.33
0.2.4
1
openbas/caldera-server:5.1.0a277796d9724
tmp@0.0.33
0.2.4
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tmp@0.2.1
0.2.4
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
tmp@0.2.1
0.2.4
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
tmp@0.2.1
0.2.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.