StackRadar

CVE-2025-64756

High

Advisory

Published 17 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
378
deployed by those charts
Fix available
1 of 1
affected package

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 378 images.

Affected packageAffected versionsFixed inImages
globnpm10.2.2, 10.2.4, 10.2.7, 10.3.1+12 more10.5.0, 11.1.0378
OSV records
GHSA-5j98-mcp5-4vw2

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
glob@10.3.12
10.5.0

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
glob@10.4.5
10.5.0

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
glob@10.4.5
10.5.0

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
glob@10.3.12
10.5.0

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-64756.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
glob@10.2.2
10.5.0

Open the chart page →

1,589

Container images carrying it

378 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
glob@10.4.5
10.5.0
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
glob@10.4.2
10.5.0
4
rcdelacruz/my-strapi-app:js-amd6438007f358355
glob@10.3.10
10.5.0
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
glob@10.4.5
10.5.0
3
epamedp/krci-portal:0.8.0687acf641097
glob@10.3.12
10.5.0
2
ethersphere/bee-localchain:latest0558799ca992
glob@10.3.10
10.5.0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
glob@10.2.4
10.5.0
2
gradiant/open5gs-webui:2.7.5fbd10c017541
glob@10.3.10
10.5.0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
glob@11.0.0
11.1.0
2
infisical/infisical:latest:v0.165.602082bf13163
glob@10.4.5
10.5.0
2
langgenius/dify-sandbox:0.2.009b7e8705673
glob@10.3.10
10.5.0
2
library/mongo-express:1.0.2:latest1b23d7976f02
glob@10.3.12
10.5.0
2
louislam/uptime-kuma:2.5.4917318f9d7be
glob@10.3.16
10.5.0
2
louislam/uptime-kuma:2.3.29aeb4e51d038
glob@10.3.16
10.5.0
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
glob@10.3.16
10.5.0
2
mojaloop/reporting:v12.1.0d480a62103d6
glob@10.4.2
10.5.0
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
glob@10.4.5
10.5.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
glob@10.4.5
10.5.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
glob@10.4.5
10.5.0
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
glob@10.3.10
10.5.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
glob@11.0.3
11.1.0
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
glob@10.3.10
10.5.0
2
rajnandan1/kener:3.2.1930407afca731
glob@11.0.1
11.1.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
glob@10.2.7
10.5.0
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
glob@10.3.10
10.5.0
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
glob@10.4.2
10.5.0
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
glob@10.4.5
10.5.0
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
glob@10.4.2
10.5.0
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
glob@10.4.5
10.5.0
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
glob@10.3.10
10.5.0
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
glob@10.4.5
10.5.0
2
activepieces/activepieces:0.23.0c26188b44e62
glob@10.3.12
10.5.0
1
actualbudget/actual-server:25.3.158fecd9088b7
glob@10.4.2
10.5.0
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
glob@10.4.5
10.5.0
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
glob@10.4.5
10.5.0
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
glob@10.4.2
10.5.0
1
alquimiaai/studio:certification38a1f0341982
glob@10.4.2
10.5.0
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
glob@10.4.2
10.5.0
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
glob@10.4.2
10.5.0
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
glob@10.4.2
10.5.0
1
assistiot/multi-link_client:latestcf048365d042
glob@10.3.10
10.5.0
1
assistiot/multi-link_server:latestf38c76a4c960
glob@10.3.3
10.5.0
1
automatischio/automatisch:0.15.03bace7a12d5f
glob@10.4.5
10.5.0
1
baserow/baserow:1.30.1df0c42eb67e8
glob@10.3.10
10.5.0
1
belirta/beli-docker:v1.0.0f65ad0e23b4d
glob@10.2.4
10.5.0
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
glob@10.4.2
10.5.0
1
bluerange/bluerange-mosquitto:25f1bfbba84832
glob@10.4.5
10.5.0
1
bnjbvr/kresus:0.22.137e216b182c8
glob@10.4.2
10.5.0
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
glob@10.4.5
10.5.0
1
ccjacobs14/amazon:59a9b14a6f09e
glob@10.3.10
10.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.