StackRadar

CVE-2025-64756

High

Advisory

Published 17 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
378
deployed by those charts
Fix available
1 of 1
affected package

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 378 images.

Affected packageAffected versionsFixed inImages
globnpm10.2.2, 10.2.4, 10.2.7, 10.3.1+12 more10.5.0, 11.1.0378
OSV records
GHSA-5j98-mcp5-4vw2

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
glob@10.3.12
10.5.0

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
glob@10.4.5
10.5.0

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
glob@10.4.5
10.5.0

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glob@10.3.12
10.5.0

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
glob@10.2.2
10.5.0

Open the chart page →

1,589

Container images carrying it

378 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
glob@10.4.5
10.5.0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
glob@10.4.5
10.5.0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
glob@10.4.5
10.5.0
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
glob@10.4.5
10.5.0
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
glob@10.4.5
10.5.0
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
glob@10.4.5
10.5.0
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
glob@10.4.2
10.5.0
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
glob@10.4.5
10.5.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
glob@10.3.10
10.5.0
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
glob@10.3.10
10.5.0
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
glob@10.4.5
10.5.0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
glob@10.4.5
10.5.0
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
glob@10.4.5
10.5.0
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
glob@10.4.5
10.5.0
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
glob@10.4.2
10.5.0
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
glob@11.0.1
11.1.0
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
glob@10.4.5
10.5.0
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
glob@10.4.2
10.5.0
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
glob@10.3.12
10.5.0
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
glob@10.3.3
10.5.0
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
glob@10.3.10
10.5.0
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
glob@10.4.1
10.5.0
1
quay.io/mittwald/kube-mail:latest04f1099241fc
glob@10.4.2
10.5.0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
glob@10.3.10
10.5.0
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
glob@10.4.2
10.5.0
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
glob@10.4.5
10.5.0
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
glob@10.4.2
10.5.0
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
glob@10.4.2
10.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.