File System Permissions Vulnerability in Melange by Chainguard
CVE-2025-54059
What is CVE-2025-54059?
A vulnerability in the Melange packaging tool allows for improper file system permissions in APKs. Specifically, versions from 0.23.0 up to, but not including, 0.29.5 set SBOM files' permissions to mode 666, granting unprivileged users the ability to modify these files on running images. Such modifications can mislead security scanners, raising significant concerns about the integrity of the APKs. In certain scenarios, an attacker could also exploit this flaw to initiate a denial of service (DoS) attack. The issue has been addressed in version 0.29.5, ensuring improved security against these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
melange >= 0.23.0, < 0.29.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
