StackRadar

CVE-2025-64756

High

Advisory

Published 17 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
378
deployed by those charts
Fix available
1 of 1
affected package

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 378 images.

Affected packageAffected versionsFixed inImages
globnpm10.2.2, 10.2.4, 10.2.7, 10.3.1+12 more10.5.0, 11.1.0378
OSV records
GHSA-5j98-mcp5-4vw2

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
glob@10.3.12
10.5.0

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
glob@10.4.5
10.5.0

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
glob@10.4.5
10.5.0

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glob@10.3.12
10.5.0

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
glob@10.2.2
10.5.0

Open the chart page →

1,589

Container images carrying it

378 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
veecode/devportal-admin-ui:0.4.30c69fd286b489
glob@10.4.2
10.5.0
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
glob@10.3.4
10.5.0
1
visualregressiontracker/migration:5.0.1f983a1d4306e
glob@10.2.4
10.5.0
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
glob@10.2.7
10.5.0
1
vlebediantsev/notes-admin-front:latest007c6670ff48
glob@10.2.7
10.5.0
1
vlebediantsev/notes-project-front:latest945675fd2636
glob@10.2.7
10.5.0
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
glob@10.2.7
10.5.0
1
wettyoss/wetty:latest7423b3d40ba2
glob@10.4.5
10.5.0
1
winfred008/amazon:910a68de5b398
glob@10.3.10
10.5.0
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glob@10.3.12
10.5.0
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
glob@10.3.10
10.5.0
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
glob@10.4.2
10.5.0
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
glob@10.4.2
10.5.0
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
glob@10.4.5
10.5.0
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
glob@10.4.5
10.5.0
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
glob@10.4.5
10.5.0
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
glob@10.4.5
10.5.0
1
zimengxiong/excalidash-backend:0.4.271273af713c91
glob@10.4.2
10.5.0
1
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
glob@10.4.2
10.5.0
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
glob@10.4.5
10.5.0
1
ghcr.io/0xemma/reddark:main2a115e991894
glob@10.2.4
10.5.0
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
glob@10.4.5
10.5.0
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
glob@10.4.2
10.5.0
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
glob@10.2.2
10.5.0
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
glob@10.2.7
10.5.0
1
ghcr.io/ajnart/homarr:lateste103abadfb52
glob@10.2.2
10.5.0
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
glob@10.3.10
10.5.0
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
glob@10.4.2
10.5.0
1
ghcr.io/argonix-io/argonix-api-frontend:1.0.0b6a67099e4c5
glob@10.4.2
10.5.0
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
glob@10.4.2
10.5.0
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
glob@10.4.2
10.5.0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
glob@10.3.10
10.5.0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
glob@10.4.5
10.5.0
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
glob@10.4.2
10.5.0
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
glob@10.4.2
10.5.0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
glob@10.4.2
10.5.0
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
glob@10.4.2
10.5.0
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
glob@10.4.5
10.5.0
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
glob@10.4.5
10.5.0
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
glob@10.4.5
10.5.0
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
glob@10.4.2
10.5.0
1
ghcr.io/caninehq/canine:latesta058034ca006
glob@10.4.5
10.5.0
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
glob@10.2.7
10.5.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
glob@10.4.5
10.5.0
1
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
glob@10.4.2
10.5.0
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
glob@11.0.3
11.1.0
1
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
glob@10.3.10
10.5.0
1
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
glob@10.3.10
10.5.0
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
glob@10.3.10
10.5.0
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
glob@10.4.2
10.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.