StackRadar

CVE-2025-69264

High

Advisory

Published 7 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.010
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
1 of 1
affected package

pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
pnpmnpm10.3.0, 10.4.0, 10.8.0, 10.12.1+6 more10.26.012
OSV records
GHSA-379q-355j-w6rj

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
pnpm@10.22.0
10.26.0

Open the chart page →

19,391
umamichristianhuthVerified publisher7.13.01 of 2See more

umami christianhuth 7.13.0

1 of the 2 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
pnpm@10.24.0
10.26.0

Open the chart page →

2,367
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
pnpm@10.3.0
10.26.0

Open the chart page →

17,245
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
pnpm@10.4.0
10.26.0

Open the chart page →

5,564
litlyxlitlyx0.2.02 of 5See more

litlyx litlyx 0.2.0

2 of the 5 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
pnpm@10.23.0
10.26.0
litlyx/litlyx-producer:latest10407f36613f
pnpm@10.23.0
10.26.0

Open the chart page →

7,874
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
pnpm@10.15.1
10.26.0

Open the chart page →

7,035
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
pnpm@10.17.0
10.26.0
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
pnpm@10.17.0
10.26.0

Open the chart page →

18,293
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pnpm@10.8.0
10.26.0

Open the chart page →

14,559
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
pnpm@10.12.1
10.26.0

Open the chart page →

24,400
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2025-69264.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
pnpm@10.25.0
10.26.0

Open the chart page →

4,016

Container images carrying it

12 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chocobozzz/peertube:v8.1.5052712130691
pnpm@10.15.1
10.26.0
1
docmost/docmost:0.95.041c8d777cf23
pnpm@10.4.0
10.26.0
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
pnpm@10.22.0
10.26.0
1
litlyx/litlyx-consumer:latest02225e77d316
pnpm@10.23.0
10.26.0
1
litlyx/litlyx-producer:latest10407f36613f
pnpm@10.23.0
10.26.0
1
openmined/syft-frontend:0.9.5d11524a3854a
pnpm@10.3.0
10.26.0
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
pnpm@10.12.1
10.26.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pnpm@10.8.0
10.26.0
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
pnpm@10.17.0
10.26.0
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
pnpm@10.17.0
10.26.0
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
pnpm@10.25.0
10.26.0
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
pnpm@10.24.0
10.26.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.