A high-severity path traversal vulnerability, tracked as CVE-2025-62725, was discovered in Docker Compose's handling of OCI-based Compose artifacts. The flaw allowed attackers to exploit the way Docker Compose processed layer annotations such as com.docker.compose.file and com.docker.compose.envfile, enabling them to escape the intended cache directory and write arbitrary files to the host system. This vulnerability could be triggered by tricking a user into referencing a malicious remote artifact, and affected a wide range of environments including Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, and cloud development environments.
The vulnerability was rated High with a CVSS score of 8.9 and could be exploited even through read-only commands like docker compose config or docker compose ps. The issue was patched in Docker Compose version v2.40.2, and users are strongly advised to upgrade to this version or later to mitigate the risk. The vulnerability was responsibly disclosed and detailed technical analysis, including proof of concept and exploitation scenarios, has been published to aid defenders in understanding and addressing the issue.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
By 2025-10-28, public technical analysis described how CVE-2025-62725 could be triggered through commands such as `docker compose ps` or `docker compose config`, not only when starting containers. A proof of concept demonstrated overwriting `~/.ssh/authorized_keys` to gain SSH access after a victim referenced a crafted remote artifact.
On 2025-10-27, Docker issued a security advisory for CVE-2025-62725 affecting Docker Compose versions prior to v2.40.2. The advisory warned that OCI artifact layer annotations could be abused for arbitrary file overwrite and urged users to upgrade.
On 2025-10-27, Docker confirmed CVE-2025-62725, a high-severity path traversal flaw in Docker Compose's OCI artifact handling, and released Docker Compose v2.40.2 to address it. The fix added path validation to prevent writes outside the cache directory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecyber.gc.ca
Open sourceimperva.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.