StackRadar

CVE-2025-64756

High

Advisory

Published 17 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
378
deployed by those charts
Fix available
1 of 1
affected package

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 378 images.

Affected packageAffected versionsFixed inImages
globnpm10.2.2, 10.2.4, 10.2.7, 10.3.1+12 more10.5.0, 11.1.0378
OSV records
GHSA-5j98-mcp5-4vw2

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
glob@10.3.12
10.5.0

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
glob@10.4.5
10.5.0

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
glob@10.4.5
10.5.0

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glob@10.3.12
10.5.0

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
glob@10.2.2
10.5.0

Open the chart page →

1,589

Container images carrying it

378 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
instill/console:0.68.54cd70e2df5c6
glob@10.4.2
10.5.0
1
instructure/kinesalite:latest34400d82f28f
glob@10.2.7
10.5.0
1
intelloop/atlas-cmms-frontend:v1.5.12409c2a00ab6
glob@10.3.10
10.5.0
1
jaedb/iris:latest048cfbf58d57
glob@10.4.2
10.5.0
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
glob@10.4.2
10.5.0
1
jkroepke/github_exporter:1.8.03d850992786d
glob@10.4.5
10.5.0
1
joplin/server:latest3f7b852959aa
glob@10.3.1
10.5.0
1
joplin/server:3.0-beta52af57880c0e
glob@10.3.1
10.5.0
1
joplin/server:2.14.2-betab87564ef34e9
glob@10.3.1
10.5.0
1
josepht05/nodejs-feb24:latest36cb0c618c94
glob@10.3.10
10.5.0
1
josepht05/titajo-docker:v1.0.0d94024965d78
glob@10.3.3
10.5.0
1
josh5/unmanic:0.2.64d49c4816260
glob@10.3.10
10.5.0
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
glob@10.4.2
10.5.0
1
kitware/cdash:v5.3.0d7767d9b9da4
glob@10.3.10
10.5.0
1
ktitilayo2/nodejswebapp:latest8bac28058688
glob@10.3.3
10.5.0
1
kubebb/component-store:latestfd8ecbd73213
glob@10.3.3
10.5.0
1
kubevious/backend:1.2.22d9ba6eb46b6
glob@10.3.10
10.5.0
1
kubevious/parser:1.2.299ae7a5168c2
glob@10.3.10
10.5.0
1
laly9999/node-app:1dd0e503913e1
glob@10.4.2
10.5.0
1
laly9999/node-app-dockerized:latest75ae77a20c6c
glob@10.3.10
10.5.0
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
glob@10.4.5
10.5.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
glob@10.4.5
10.5.0
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
glob@10.3.10
10.5.0
1
langgenius/dify-web:1.16.187dd47e4e28f
glob@10.4.5
10.5.0
1
langgenius/dify-web:0.6.11a2a294743634
glob@10.3.10
10.5.0
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
glob@10.4.5
10.5.0
1
langgenius/dify-web:1.0.0d64914ff0d6d
glob@10.4.2
10.5.0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
glob@10.4.5
10.5.0
1
library/ghost:5.79.083f7bf209844
glob@10.3.10
10.5.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
glob@10.4.5
10.5.0
1
library/kibana:7.17.150172f1c538e7
glob@10.3.3
10.5.0
1
library/kibana:8.18.004c0fc150f3a
glob@10.4.5
10.5.0
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
glob@10.4.2
10.5.0
1
library/node:18-alpine8d6421d663b4
glob@10.4.2
10.5.0
1
library/node:208f693eaa7e0a
glob@10.4.2
10.5.0
1
lissy93/domain-locker:latestd3c95edc0a8b
glob@10.4.2
10.5.0
1
lissy93/networking-toolbox:latest700862839553
glob@10.4.5
10.5.0
1
litlyx/litlyx-consumer:latest02225e77d316
glob@10.4.5
10.5.0
1
litlyx/litlyx-dashboard:lateste64ff2d52385
glob@10.4.5
10.5.0
1
litlyx/litlyx-producer:latest10407f36613f
glob@10.4.5
10.5.0
1
localstack/localstack:3.19d278167f2b7
glob@10.3.10
10.5.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
glob@10.4.5
10.5.0
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
glob@10.3.1
10.5.0
1
louislam/uptime-kuma:13d632903e6af
glob@10.3.12
10.5.0
1
louislam/uptime-kuma:2.5.33e24e96c89ef
glob@10.3.16
10.5.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
glob@10.3.16
10.5.0
1
louislam/uptime-kuma:2.4.091e963bfda56
glob@10.3.16
10.5.0
1
louislam/uptime-kuma:1.23.1396510915e6be
glob@10.3.10
10.5.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
glob@10.4.2
10.5.0
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
glob@10.3.12
10.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.