CVE-2025-65965
HIGHGrype 0.68.0-0.104.0 - Credential Disclosure via JSON Output File
Title source: llmDescription
Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found in Grype, affecting versions 0.68.0 through 0.104.0. If registry credentials are defined and the output of grype is written using the --file or --output json=<file> option, the registry credentials will be included unsanitized in the output file. This issue has been patched in version 0.104.1. Users running affected versions of grype can work around this vulnerability by redirecting stdout to a file instead of using the --file or --output options.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/anchore/grype/security/advisories/GHSA-6gxw-85q2-q646
Issue Tracking x_refsource_misc
https://github.com/anchore/grype/pull/3068
Patch x_refsource_misc
https://github.com/anchore/grype/commit/39f7fa17af2739cafe9b27176d4a68f7c05f21c1
Scores
CVSS v4
8.2
EPSS
0.0013
EPSS Percentile
2.5%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-212
Status
published
Products (2)
anchore/grype
0.68.0 - 0.104.1Go
anchore/grype
>= 0.68.0, < 0.104.1
Published
Nov 25, 2025
Tracked Since
Feb 18, 2026