PT-2025-34689 · Docker+1 · Docker+1
Privt00
·
Published
2025-08-25
·
Updated
2025-08-26
·
CVE-2025-57802
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Airlink versions prior to 1.0.1
Description:
Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. An attacker with access to the affected container can create symbolic links inside the mounted directory (
/app/data). These symlinks can point to sensitive locations on the host filesystem due to the container bind-mounting an arbitrary host path. When the application or other processes follow these symlinks, the attacker can gain unauthorized read access to host files outside the container.Recommendations:
Update to version 1.0.1 or later.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airlink
Docker