CVE-2025-6587

MEDIUM

Docker Desktop <4.43.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

Scores

CVSS v4 5.2
EPSS 0.0010
EPSS Percentile 27.8%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-532
Status published
Products (1)
Docker/Docker Desktop < 4.43.0
Published Jul 03, 2025
Tracked Since Feb 18, 2026