CVE-2025-67746
MediumAdvisory
Published 30 Dec 2025In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.1
- base score, highest
- EPSS
- 0.005
- 39th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 5
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Composer is vulnerable to ANSI sequence injection
Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| composer/ | 2.1.11, 2.1.14, 2.2.12 | 2.2.26 | 4 |
| composerbitnami | 2.8.10 | 2.2.26 | 1 |
- OSV records
- BIT-composer-2025-67746GHSA-59pp-r3rg-353g
Charts affected
5 by stars
Container images carrying it
5 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bitnamilegacy/ | f02c000c54b1 | composer | 2.2.26 | 1 |
| mautic/ | 94ea4acf4049 | composer/ | 2.2.26 | 1 |
| shyim/ | a951c0e6b836 | composer/ | 2.2.26 | 1 |
| solidnerd/ | 762ffd5c51d3 | composer/ | 2.2.26 | 1 |
| ghcr.io/ | f05447347ff1 | composer/ | 2.2.26 | 1 |