Description
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21896 | apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files |
Github GHSA |
GHSA-x6ph-r535-3vjw | apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files |
References
History
Tue, 22 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue. | |
| Title | apko has incorrect permission (0666) in /etc/ld.so.cache and other files | |
| Weaknesses | CWE-276 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-22T15:03:42.966Z
Reserved: 2025-07-14T17:23:35.262Z
Link: CVE-2025-53945
Updated: 2025-07-22T15:03:39.488Z
Status : Deferred
Published: 2025-07-18T16:15:30.020
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-53945
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA