Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21889 | melange's world-writable permissions expose SBOM files to potential image tampering |
Github GHSA |
GHSA-5662-cv6m-63wh | melange's world-writable permissions expose SBOM files to potential image tampering |
Fri, 18 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Jul 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue. | |
| Title | melange creates SBOM files in APKs with world-writable permissions | |
| Weaknesses | CWE-276 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-18T16:04:30.154Z
Reserved: 2025-07-16T13:22:18.203Z
Link: CVE-2025-54059
Updated: 2025-07-18T15:53:59.807Z
Status : Deferred
Published: 2025-07-18T16:15:30.180
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54059
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA