CVE-2025-15558
unknown
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
โ
Description
Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/docker/cli | >=19.03.0,<29.2.0 | 29.2.0 |
| Go | github.com/docker/cli | <29.2.0+incompatible | 29.2.0+incompatible |
| Go | github.com/docker/compose | | |
| Go | github.com/docker/compose/v2 | >=2.31.0 | |
| Go | github.com/docker/compose/v5 | <5.1.0 | 5.1.0 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| gcp | | |
References
- https://github.com/docker/cli/security/advisories/GHSA-p436-gjf2-799p
- https://nvd.nist.gov/vuln/detail/CVE-2025-15558
- https://github.com/docker/cli/pull/6713
- https://github.com/docker/compose/pull/12300
- https://github.com/docker/cli/commit/13759330b1f7e7cb0d67047ea42c5482548ba7fa
- https://docs.docker.com/desktop/release-notes
- https://github.com/docker/cli
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-28304
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.