File System Permissions Vulnerability in Melange by Chainguard
CVE-2025-54059
4.4MEDIUM
What is CVE-2025-54059?
A vulnerability in the Melange packaging tool allows for improper file system permissions in APKs. Specifically, versions from 0.23.0 up to, but not including, 0.29.5 set SBOM files' permissions to mode 666, granting unprivileged users the ability to modify these files on running images. Such modifications can mislead security scanners, raising significant concerns about the integrity of the APKs. In certain scenarios, an attacker could also exploit this flaw to initiate a denial of service (DoS) attack. The issue has been addressed in version 0.29.5, ensuring improved security against these risks.
Affected Version(s)
melange >= 0.23.0, < 0.29.5