HIGH 7.4 Go

Podman Creates Temporary File with Insecure Permissions

GHSA-m68q-4hqr-mc6f · CVE-2025-4953 · GO-2025-3961

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

Ready to move

Start Securing

Free, no credit card | First findings in minutes