GHSA-vmg3-7v43-9g23 · Severity: critical · Ecosystem: go — NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Conclusion & alert: CVE-2025-23266 is rated Moderate Risk (49.2/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.17%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-13 | 0.05% | 0.17% | +0.11% |
| 2 | 2026-03-03 | 0.05% | 0.05% | +0.01% |
| 3 | 2025-11-21 | — | 0.05% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
GHSA-vmg3-7v43-9g23 · Severity: critical · Ecosystem: go — NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-23266 |
suse
|
critical | CVE-2025-23266 severity critical: SUSE including 2 source package names (govulncheck-vulndb-0.0.20251023T162509-1.1, nvidia-container-toolkit-1.18.0-150200.5.17.1), 18 product×package rows across 18 product lines (SUSE Enterprise Storage 7.1, SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS, … (18 product lines)): Fixed 18. | https://www.suse.com/security/cve/CVE-2025-23266/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||