CVE-2025-9566

Executive Summary

CVE-2025-9566 exposes a flaw in Podman’s kube play command that lets an attacker overwrite arbitrary host files via a symlink in a Secret or ConfigMap volume mount. The attacker can specify the target file but cannot control the written content. The issue exists from Podman v4.0.0 onward and is fixed in v5.6.1. It is not currently listed in the CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2025-09-05T20:15:36.727 - Last Modified: 2026-09-28T02:17:17.800

Original Description: There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file.

Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

"There are two primary choices in life: to accept conditions as they exist, or accept responsibility for changing them."

— Denis Waitley
Source: NVD