🛡️ CVE-2025-59054

⚪ Unknown ✅ No Known Exploit CWE-552 NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execution environments. In versions of dstack prior to 0.5.4, a malicious host may provide a crafted LUKS2 data volume to a dstack CVM for use as the /data mount. The guest will open the volume and write secret data using a volume key known to the attacker, causing disclosure of Wireguard keys and other secret information. The attacker can also pre-load data on the device, which could potentially compromise guest execution. LUKS2 volume metadata is not authenticated and supports null key-encryption algorithms, allowing an attacker to create a volume such that the volume opens (cryptsetup open) without error using any passphrase or token, records all writes in plaintext (or ciphertext with an attacker-known key), and/or contains arbitrary data chosen by the attacker. Version 0.5.4 of dstack contains a patch that addresses LUKS headers.

Weakness class

CVE-2025-59054 is classified as CWE-552: Files or Directories Accessible to External Parties. Files intended to stay internal are reachable from outside the application.

Affected software

CVE-2025-59054 is recorded against 1 package.

  • unknown

Timeline and source

Published on 12 September 2025 and last revised on 17 June 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com
github.com
github.com
gitlab.com
blog.trailofbits.com

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE CWE-552
Public Exploit âś… No
Source NVD
Published 2025-09-12
Updated 2026-08-11
Modified 2026-06-17
Fix URL N/A

Affected Packages

Software From version Fixed in
unknown — —

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2025-59054?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2025-59054 and other known CVE records.

Scan My Site Free →

No credit card required  Â·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.