StackRadar

CVE-2025-64756

High

Advisory

Published 17 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
378
deployed by those charts
Fix available
1 of 1
affected package

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 378 images.

Affected packageAffected versionsFixed inImages
globnpm10.2.2, 10.2.4, 10.2.7, 10.3.1+12 more10.5.0, 11.1.0378
OSV records
GHSA-5j98-mcp5-4vw2

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
glob@10.3.12
10.5.0

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
glob@10.4.5
10.5.0

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
glob@10.4.5
10.5.0

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glob@10.3.12
10.5.0

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
glob@10.2.2
10.5.0

Open the chart page →

1,589

Container images carrying it

378 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chainsafe/lodestar:latest5593f6e97912
glob@11.0.0
11.1.0
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
glob@10.4.5
10.5.0
1
chibisafe/chibisafe:latest836467a50792
glob@10.4.2
10.5.0
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
glob@10.3.10
10.5.0
1
chocobozzz/peertube:v8.1.5052712130691
glob@10.4.2
10.5.0
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
glob@10.4.5
10.5.0
1
contane/foreman:0.5.2efb98bdcc4e9
glob@10.4.5
10.5.0
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
glob@11.0.1
11.1.0
1
countly/api:25.05.4f4cc7447c4f5
glob@10.3.12
10.5.0
1
countly/countly-server:25.05.4e3c238248f99
glob@10.3.12
10.5.0
1
countly/frontend:25.05.42acbc11499b6
glob@10.3.12
10.5.0
1
cryptexlabs/authf:0.12.11189c07411d7c
glob@11.0.0
11.1.0
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
glob@10.3.10
10.5.0
1
dacinfomotion/h2p:latest68fa393b472c
glob@10.2.7
10.5.0
1
davdiv/musicociel:deva85f99be882c
glob@10.3.10
10.5.0
1
dbgate/dbgate:7.2.0-alpine287077002446
glob@10.4.2
10.5.0
1
defactops/defactops-backend:1.0.2307b663c0092a
glob@10.3.10
10.5.0
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
glob@11.0.0
11.1.0
1
devkrishan001/backend:latestf1c3acadeabe
glob@10.4.2
10.5.0
1
devravinder/node-express-app:1.0.05325a96967b5
glob@10.4.5
10.5.0
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
glob@10.2.2
10.5.0
1
directus/directus:11.1.0e3c8bb975350
glob@10.3.12
10.5.0
1
diygod/rsshub:2025-11-097a6312cac0d5
glob@10.4.5
10.5.0
1
docmost/docmost:0.95.041c8d777cf23
glob@10.4.5
10.5.0
1
documenso/documenso:v1.8.17f16a9449f18
glob@10.4.2
10.5.0
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
glob@10.3.10
10.5.0
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
glob@10.4.5
10.5.0
1
ethersphere/etherproxy:1.0.056029b0985f4
glob@10.2.7
10.5.0
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
glob@10.4.5
10.5.0
1
ethpandaops/ethereumjs:masterfb84b718500f
glob@10.4.2
10.5.0
1
fallenbagel/jellyseerr:latest4538137bc5af
glob@10.4.5
10.5.0
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
glob@10.3.12
10.5.0
1
felipecs8/conversor-temperatura:v1f945423be36d
glob@10.4.2
10.5.0
1
felipecs8/landing-page:v1db6d44e325a1
glob@10.4.5
10.5.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
glob@10.4.2
10.5.0
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
glob@10.4.5
10.5.0
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
glob@10.4.5
10.5.0
1
folioci/mod-graphql:latestf0655a6a08fd
glob@10.4.2
10.5.0
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
glob@10.3.12
10.5.0
1
fosrl/pangolin:1.13.0c32ad797ab96
glob@10.4.5
10.5.0
1
glenndehaan/kube-hook:latest0a7116f48bfe
glob@10.4.5
10.5.0
1
hamid2021/nodejs-dockercli:latest429d99890c3c
glob@10.3.10
10.5.0
1
hansehe/graphql-gateway:1.0.458e09540afbc
glob@10.3.3
10.5.0
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
glob@10.2.4
10.5.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
glob@10.4.2
10.5.0
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
glob@10.2.7
10.5.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
glob@10.4.5
10.5.0
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
glob@10.4.2
10.5.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
glob@10.4.5
10.5.0
1
ilum/marquez-web:0.53.2716437a51a6c
glob@10.4.5
10.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.