StackRadar

CVE-2025-8869

Medium

Advisory

Published 24 Sept 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,079
of 17,781 indexed, latest versions
Container images
1,131
deployed by those charts
Fix available
2 of 3
affected packages

pip's fallback tar extraction doesn't check symbolic links point to extraction directory

Carried by container images the latest versions of 1,079 of 17,781 indexed charts deploy, on 1,131 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+62 more25.31,129
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+14 moreno fix listed97
py3-pipapk25.0.1-r0, 25.2-r025.2-r22
OSV records
CGA-2c2v-qg5x-gf3vCGA-2h56-9hwm-vvwrDEBIAN-CVE-2025-8869GHSA-4xh5-x5gv-qwphUBUNTU-CVE-2025-8869
Also known as
CGA-2j52-82cx-jqm7, CGA-2vvp-4788-p685, CGA-38mx-66cv-5xhm, CGA-96x5-ppvf-355h, CGA-c923-5fqp-9gx9, CGA-c9f4-7rjc-ch6m, CGA-fvxf-h26j-p86m, CGA-h22m-qp2v-7fj8, CGA-m95p-j3wh-8jw6, CGA-w6hh-8hcg-xmhc, PYSEC-2026-1795

Charts affected

1,079 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackbook-k8sinfra-v265.5.11 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

1 of the 6 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
pip@24.2
25.3

Open the chart page →

6,036
puppetboardbootcVerified publisher0.1.41 of 1See more

puppetboard bootc 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
bootc/puppetboard:1.1.0f1383295e7be
pip@19.2.3
25.3

Open the chart page →

1,292
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
pip@24.0
25.3

Open the chart page →

27,274
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
25.3

Open the chart page →

2,018
medusabryanalves0.1.01 of 1See more

medusa bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
25.3

Open the chart page →

147
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
25.3

Open the chart page →

2,504
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
pip@9.0.0
25.3

Open the chart page →

923
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pip@20.3.4
25.3

Open the chart page →

2,573
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pip@22.0.4
25.3

Open the chart page →

2,507
bucket-clonercamptocamp31.0.41 of 1See more

bucket-cloner camptocamp3 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
camptocamp/bucket-cloner:latestacfafc308d88
pip@21.2.1
25.3

Open the chart page →

4,518
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
pip@20.0.2
25.3

Open the chart page →

3,891
pghoardcamptocamp35.8.11 of 1See more

pghoard camptocamp3 5.8.1

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
camptocamp/pghoard:10bff736b15623
pip@18.1
25.3

Open the chart page →

2,813
prometheus-operatorcamptocamp35.15.11 of 5See more

prometheus-operator camptocamp3 5.15.1

1 of the 5 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pip@19.0.3
25.3

Open the chart page →

2,490
snow-webhookcamptocamp31.0.01 of 1See more

snow-webhook camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
camptocamp/snow-webhook:latest2924b43dbf40
pip@18.1
25.3

Open the chart page →

1,310
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
pip@24.3.1
25.3

Open the chart page →

10,776
castai-hibernatecastaiVerified publisher0.2.121 of 1See more

castai-hibernate castai 0.2.12

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
castai/hibernate:v0.14da62858c8381
pip@23.0.1
25.3

Open the chart page →

1,146
temporalcastaiVerified publisher0.54.21 of 14See more

temporal castai 0.54.2

1 of the 14 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
pip@24.0
25.3

Open the chart page →

16,198
catalyst-agentscatalyst-agents0.1.301 of 18See more

catalyst-agents catalyst-agents 0.1.30

1 of the 18 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
pip@25.0.1
25.3

Open the chart page →

15,027
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
pip@8.1.2
25.3

Open the chart page →

12,018
opencvecfi20170.1.22 of 7See more

opencve cfi2017 0.1.2

2 of the 7 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
pip@24.3.1
25.3
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
pip@25.0.1
25.3

Open the chart page →

15,371
pypi-servercgsimmons0.1.01 of 1See more

pypi-server cgsimmons 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v1.3.2303ac89b2aa2
pip@19.3.1
25.3

Open the chart page →

506
ctk-walkthroughchaostoolkit-walkthrough0.1.03 of 3See more

ctk-walkthrough chaostoolkit-walkthrough 0.1.0

3 of the 3 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
chaostoolkit/back:latest734f3af86125
pip@20.2.4
25.3
chaostoolkit/front:latest7f4a7eb9f7df
pip@20.2.4
25.3
chaostoolkit/middle:latestb95ba4961cfc
pip@20.3
25.3

Open the chart page →

5,557
suggestarrcharliecharts0.4.41 of 1See more

suggestarr charliecharts 0.4.4

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
ciuse99/suggestarr:v1.0.20d72768245ef5
pip@24.3.1
25.3

Open the chart page →

1,126
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
pip@25.0.1
25.3

Open the chart page →

4,911
home-assistant-otbrcharts-derwitt-devVerified publisher2.1.31 of 1See more

home-assistant-otbr charts-derwitt-dev 2.1.3

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/homeassistant-otbr:4.2.31b53b0b3488e
pip@25.1.1
python-pip@25.1.1+dfsg-1
25.3
no fix listed

Open the chart page →

2,346
chat-searchchat-searchVerified publisher0.1.71 of 1See more

chat-search chat-search 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
ghcr.io/hemslo/chat-search:latest39d48995a5bd
pip@24.0
25.3

Open the chart page →

4,042
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
conduction/checkin-component-varnish:devef3a3fb0ad47
pip@9.0.1
25.3

Open the chart page →

8,408
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
pip@21.1.1
25.3
countly/frontend:25.05.42acbc11499b6
pip@21.1.1
25.3

Open the chart page →

7,295
kube-ops-viewchristianhuthVerified publisher8.3.31 of 1See more

kube-ops-view christianhuth 8.3.3

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
pip@22.3.1
25.3

Open the chart page →

1,227
syncserverchristianhuthVerified publisher1.3.01 of 1See more

syncserver christianhuth 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
mozilla/syncserver:latest016162bf39d8
pip@20.3.4
25.3

Open the chart page →

1,382
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pip@22.0.2
25.3

Open the chart page →

20,900
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pip@10.0.1
25.3

Open the chart page →

2,408
couchdbcloudnativeapp1.1.31 of 3See more

couchdb cloudnativeapp 1.1.3

1 of the 3 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
kocolosk/couchdb-statefulset-assembler:1.2.06effb982154e
pip@9.0.1
25.3

Open the chart page →

2,110
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
pip@10.0.1
25.3
daskdev/dask-notebook:1.1.0052630f5ca04
pip@18.1
25.3

Open the chart page →

29,901
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
pip@9.0.1
25.3

Open the chart page →

36,094
k8s-spot-termination-handlercloudnativeapp1.2.11 of 1See more

k8s-spot-termination-handler cloudnativeapp 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
pip@19.0.3
25.3

Open the chart page →

2,095
kube-huntercloudnativeapp1.0.21 of 1See more

kube-hunter cloudnativeapp 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
aquasec/kube-hunter:1950bf607ce9308
pip@18.1
25.3

Open the chart page →

1,305
locustcloudnativeapp1.0.01 of 1See more

locust cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
greenbirdit/locust:0.9.0e99d53bdc944
pip@18.1
25.3

Open the chart page →

1,352
prometheus-operatorcloudnativeapp6.4.01 of 7See more

prometheus-operator cloudnativeapp 6.4.0

1 of the 7 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pip@19.1.1
25.3

Open the chart page →

2,954
sentry-kubernetescloudnativeapp0.2.01 of 1See more

sentry-kubernetes cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
getsentry/sentry-kubernetes:latest6ac37974fd2a
pip@19.0.3
25.3

Open the chart page →

1,415
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
pip@19.0.3
25.3

Open the chart page →

5,060
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
25.3
no fix listed

Open the chart page →

77,758
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
pip@23.2.1
25.3

Open the chart page →

25,151
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pip@22.0.4
25.3

Open the chart page →

6,695
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
pip@22.1.2
25.3

Open the chart page →

6,921
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
robotshop/rs-payment:latest774b52c6180d
pip@21.2.4
25.3

Open the chart page →

29,555
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
25.3
no fix listed

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
25.3
no fix listed

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
pip@20.0.2
python-pip@20.0.2-5ubuntu1.6
25.3
no fix listed

Open the chart page →

11,592
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2025-8869.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pip@25.0.1
25.3

Open the chart page →

4,601

Container images carrying it

1,131 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
acockburn/appdaemon:4.0.83a93281d7e94
pip@21.0.1
25.3
1
afrank/mozalert-controller:latestd463c37b08d7
pip@20.1.1
25.3
1
agentarea/agentarea-api:latest9e15e16fa758
pip@25.0.1
25.3
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
pip@25.0.1
25.3
1
agentarea/agentarea-worker:latest1e5cb68ee77a
pip@25.0.1
25.3
1
ahmetgrbzz/result_server:1.008e10f9c0f53
pip@24.0
25.3
1
ahmetgrbzz/result_server:2.035c37ae2bafd
pip@24.0
25.3
1
ahmetgrbzz/web_server:1.02e7fef69c29f
pip@24.0
25.3
1
ahmetgrbzz/web_server:2.0f018bafd2b0c
pip@24.0
25.3
1
aibrix/metadata-service:v0.7.063fb81a64377
pip@24.0
25.3
1
airbyte/manifest-server:7.23.73b3a670af168
pip@25.2
25.3
1
akeyless/base-rhel:0.0.14ba8900a0061
pip@20.2.4
25.3
1
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
pip@25.0.1
25.3
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
pip@25.0.1
25.3
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
pip@25.0.1
25.3
1
alaaamin/reload-count-tornado-py-app:v1.0.1alpine46da5844794e
pip@22.0.4
25.3
1
alakaganaguathoork/local-business:latest7eb27b0f4a5a
pip@25.0.1
25.3
1
alerta/alerta-web:8.5.04786b9eaa606
pip@20.1.1
25.3
1
alexeyr7/sf-test-app:latestdf0b41fdbd53
pip@22.0.4
25.3
1
alexvm6/generator:latestfb99ee4f760a
pip@22.3.1
25.3
1
alexvm6/pythonalex:latest89a05786879c
pip@22.3.1
25.3
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
pip@9.0.3
25.3
1
allegroai/clearml:2.0.0-613713ae38f7daf
pip@24.3.1
25.3
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.5
25.3
no fix listed
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pip@22.3.1
25.3
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pip@22.3.1
25.3
1
alpine/k8s:1.22.600ac10bcb759
pip@22.0.4
25.3
1
alpine/k8s:1.27.321b24e6bf801
pip@23.1.2
25.3
1
alpine/k8s:1.31.106dbe6f391eda
pip@25.1.1
25.3
1
alpine/k8s:1.31.137a319b15cfc9
pip@25.2
25.3
1
alpine/k8s:1.32.47e1e7d5b7a96
pip@25.1
25.3
1
alpine/k8s:1.31.49c4976d47656
pip@24.3.1
25.3
1
alpine/k8s:1.18.16a41efe02a041
pip@21.2.1
25.3
1
alpine/k8s:1.30.0bd01dae02676
pip@24.0
25.3
1
alpine/k8s:1.30.2cd560fce90f7
pip@24.1.1
25.3
1
alpine/k8s:1.28.13e5c0b053fed7
pip@24.2
25.3
1
alpine/k8s:1.32.3eec354133193
pip@25.0.1
25.3
1
alpine/k8s:1.28.2fc059f056ad0
pip@23.2.1
25.3
1
amagdi888/my-repo:hello-appd8a10fc8faf6
pip@22.0.4
25.3
1
amancevice/superset:0.28.1c8c04bfe3d66
pip@19.0.3
25.3
1
amd64/mysql:5.7e20a653e0f51
pip@23.0.1
25.3
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
pip@20.0.2
25.3
1
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
pip@20.2.2
25.3
1
amundsendev/amundsen-search:2.4.099dda9502c3e
pip@20.2.2
25.3
1
anchore/anchore-engine:v0.10.0bde9eedf639d
pip@19.3.1
25.3
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
pip@9.0.3
25.3
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
pip@22.0.2
25.3
1
andreymileshin/kube-info:v0.1.0f7b300bc9e66
pip@24.2
25.3
1
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
pip@24.2
25.3
1
apache/airflow:2.8.4-python3.964e58748b6b9
pip@24.0
25.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.