StackRadar

CVE-2025-64756

High

Advisory

Published 17 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
378
deployed by those charts
Fix available
1 of 1
affected package

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 378 images.

Affected packageAffected versionsFixed inImages
globnpm10.2.2, 10.2.4, 10.2.7, 10.3.1+12 more10.5.0, 11.1.0378
OSV records
GHSA-5j98-mcp5-4vw2

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
glob@10.3.12
10.5.0

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
glob@10.4.5
10.5.0

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
glob@10.4.5
10.5.0

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glob@10.3.12
10.5.0

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
glob@10.2.2
10.5.0

Open the chart page →

1,589

Container images carrying it

378 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/data-fair/data-fair:3cc9498b64b5b
glob@10.3.3
10.5.0
1
ghcr.io/data-fair/notify:3c739b74dabb0
glob@10.4.5
10.5.0
1
ghcr.io/data-fair/processings:15a9216989707
glob@10.3.3
10.5.0
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
glob@10.3.10
10.5.0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
glob@10.4.5
10.5.0
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
glob@10.4.2
10.5.0
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
glob@10.4.5
10.5.0
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
glob@10.4.5
10.5.0
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
glob@10.4.5
10.5.0
1
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
glob@10.4.2
10.5.0
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
glob@10.4.5
10.5.0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
glob@10.4.2
10.5.0
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
glob@10.4.2
10.5.0
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
glob@10.4.5
10.5.0
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
glob@10.4.5
10.5.0
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
glob@10.4.5
10.5.0
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
glob@10.4.5
10.5.0
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
glob@10.4.5
10.5.0
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
glob@10.4.2
10.5.0
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
glob@11.0.2
11.1.0
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
glob@11.0.2
11.1.0
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
glob@10.4.5
10.5.0
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
glob@10.4.2
10.5.0
1
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
glob@10.3.10
10.5.0
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
glob@10.4.2
10.5.0
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
glob@10.4.2
10.5.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
glob@10.3.10
10.5.0
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
glob@10.3.10
10.5.0
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
glob@10.4.2
10.5.0
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
glob@10.4.2
10.5.0
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
glob@10.4.5
10.5.0
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
glob@10.4.5
10.5.0
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
glob@11.0.3
11.1.0
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
glob@10.4.5
10.5.0
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
glob@10.4.2
10.5.0
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
glob@10.4.2
10.5.0
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
glob@10.3.10
10.5.0
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
glob@10.4.2
10.5.0
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
glob@10.4.5
10.5.0
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
glob@10.4.5
10.5.0
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
glob@10.4.5
10.5.0
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
glob@10.3.12
10.5.0
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
glob@10.4.2
10.5.0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
glob@10.4.5
10.5.0
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
glob@10.4.5
10.5.0
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
glob@10.4.2
10.5.0
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
glob@10.4.5
10.5.0
1
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
glob@10.3.10
10.5.0
1
ghcr.io/techno-tim/littlelink-server:latest735a1fcd078b
glob@10.3.10
10.5.0
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
glob@10.4.5
10.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.