StackRadar

CVE-2025-57820

High

Advisory

Published 26 Aug 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.9
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 1
affected package

devalue prototype pollution vulnerability

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
devaluenpm2.0.1, 4.3.2, 4.3.3, 5.0.05.3.219
OSV records
GHSA-vj54-72f3-p5jv

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
devalue@4.3.2
5.3.2

Open the chart page →

17,245
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
devalue@2.0.1
5.3.2

Open the chart page →

17,404
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
devalue@2.0.1
5.3.2

Open the chart page →

7,579
data-fairdata354-helmVerified publisher1.1.26 of 12See more

data-fair data354-helm 1.1.2

6 of the 12 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
devalue@2.0.1
5.3.2
ghcr.io/data-fair/metrics:0a8d40779eeae
devalue@2.0.1
5.3.2
ghcr.io/data-fair/notify:3c739b74dabb0
devalue@2.0.1
5.3.2
ghcr.io/data-fair/portals:18b621866ceb2
devalue@2.0.1
5.3.2
ghcr.io/data-fair/processings:15a9216989707
devalue@2.0.1
5.3.2
ghcr.io/data-fair/simple-directory:438a4f32fad82
devalue@2.0.1
5.3.2

Open the chart page →

38,346
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
devalue@4.3.2
5.3.2

Open the chart page →

32,501
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
devalue@2.0.1
5.3.2

Open the chart page →

3,696
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
devalue@5.0.0
5.3.2

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
devalue@5.0.0
5.3.2

Open the chart page →

16,400
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
devalue@5.0.0
5.3.2

Open the chart page →

16,400
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
devalue@5.0.0
5.3.2

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
devalue@5.0.0
5.3.2

Open the chart page →

15,635
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
devalue@4.3.3
5.3.2

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
devalue@5.0.0
5.3.2

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2025-57820.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
devalue@5.0.0
5.3.2

Open the chart page →

28,858

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
baserow/baserow:1.30.1df0c42eb67e8
devalue@2.0.1
5.3.2
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
devalue@2.0.1
5.3.2
1
ondrejsika/parking:latestb1fd497416c8
devalue@2.0.1
5.3.2
1
opea/codegen-ui:1.02bee4eb66f3e
devalue@4.3.3
5.3.2
1
opea/codetrans-ui:1.03ef121f34610
devalue@5.0.0
5.3.2
1
opea/docsum-ui:1.07f854e9bffaf
devalue@5.0.0
5.3.2
1
openmined/syft-frontend:0.9.5d11524a3854a
devalue@4.3.2
5.3.2
1
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
devalue@5.0.0
5.3.2
1
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
devalue@5.0.0
5.3.2
1
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
devalue@5.0.0
5.3.2
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
devalue@5.0.0
5.3.2
1
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
devalue@5.0.0
5.3.2
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
devalue@4.3.2
5.3.2
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
devalue@2.0.1
5.3.2
1
ghcr.io/data-fair/metrics:0a8d40779eeae
devalue@2.0.1
5.3.2
1
ghcr.io/data-fair/notify:3c739b74dabb0
devalue@2.0.1
5.3.2
1
ghcr.io/data-fair/portals:18b621866ceb2
devalue@2.0.1
5.3.2
1
ghcr.io/data-fair/processings:15a9216989707
devalue@2.0.1
5.3.2
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
devalue@2.0.1
5.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.