File System Permissions Vulnerability in Melange by Chainguard
CVE-2025-54059

4.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 July 2025

What is CVE-2025-54059?

A vulnerability in the Melange packaging tool allows for improper file system permissions in APKs. Specifically, versions from 0.23.0 up to, but not including, 0.29.5 set SBOM files' permissions to mode 666, granting unprivileged users the ability to modify these files on running images. Such modifications can mislead security scanners, raising significant concerns about the integrity of the APKs. In certain scenarios, an attacker could also exploit this flaw to initiate a denial of service (DoS) attack. The issue has been addressed in version 0.29.5, ensuring improved security against these risks.

Affected Version(s)

melange >= 0.23.0, < 0.29.5

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54059 : File System Permissions Vulnerability in Melange by Chainguard