Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-54867

23
FAUCET Score

CVE-2025-54867 is a high-severity vulnerability affecting Youki container runtime versions prior to 0.5.5. It allows a low-privileged attacker to potentially gain access to the host root filesystem if /proc and /sys within the container's rootfs are symbolic links. The vulnerability has a CVSS score of 7.0 (HIGH) due to its high impact on confidentiality, integrity, and availability, despite requiring high attack complexity. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.5.5CPE matchmatch criteria
cpe:2.3:a:youki-dev:youki:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 27th percentile among its peer group of 1,516 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rustpatch availablevia ghsa
Product: youkiFixed in: 0.5.5

Vendor Advisories (1)

rustGHSA-j26p-6wx7-f3pwhigh

Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.

Aug 14, 2025

References

github.com / youki-dev/youki/commit/0d9b4f2aa5ceaf988f3eb568711d2acf0a4ace37
Patch
github.com / youki-dev/youki/releases/tag/v0.5.5
Release Notes
github.com / youki-dev/youki/security/advisories/GHSA-j26p-6wx7-f3pw
Vendor Advisory