OVERVIEW Podman versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend where unsanitized VM image paths enable PowerShell subexpression injection. An attacker controlling the VM image path through a crafted machine name or image directory can execute arbitrary PowerShell commands. The vulnerability is exclusive to Windows systems using the HyperV backend and has been patched in version 5.8.2. SEVERITY The vulnerability presents a high-impact threat with a local attack vector and low complexity. An attacker with the ability to influence VM image paths can achieve SYSTEM-level code execution on typical Windows installations, representing complete system compromise. The relatively low EPSS score of 0.0004 suggests limited prevalence in current threat landscapes, though the potential impact remains severe for affected deployments. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the CVE's inactive status on threat feeds and its absence from the Known Exploited Vulnerabilities catalog. No public exploit code availability is documented. Community attention appears limited given the specialized nature of the vulnerability, restricted platform scope, and the availability of a timely patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.8.0, < 5.8.2CPE matchmatch criteria | cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.