Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-71424— Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

Quick assessment

Affected
edgelesssys contrast
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contrast 是 Edgeless Systems 提供的用于 Kubernetes 上机密容器的运行时系统。在 1.9.0 及更早版本中,Contrast 受到以下漏洞的影响: Dockerfile 中的 指令(对应 OCI 镜像配置中的 )仅作为提示,并不被 Kubernetes 特别处理。然而,当 Kubernetes 未指定挂载点时,containerd 会为其添加一个挂载点,这要求运行时系统能够将任意数据推送到 Kata Agent。因此,在未受影响的 AKS 部署之外,基于裸机部署的 Contras

CVSS 3.5 · Low EPSS 0.16% · P5
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-71424

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount
Source: CVE Program / CVE List V5
Vulnerability Description
Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when Kubernetes sets none, requiring the runtime to be able to push arbitrary data to the Kata agent. As a result, on bare-metal Contrast deployments (AKS deployments are not affected) that run an image declaring at least one VOLUME for which no Kubernetes mount exists at that path, the untrusted host can write arbitrary file trees below that mount point inside the confidential container, compromising the integrity of a directory that is typically important to the application's core functionality. Version 1.9.1 fixes the issue by disallowing this configuration in `contrast generate`.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
保护机制失效
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
edgelesssys contrast 0 ~ 1.9.1 -

II. Public POCs for CVE-2025-71424

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-71424

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-71424 (1)

Other References for CVE-2025-71424 (1)

Same Patch Batch · edgelesssys · 2026-09-27 · 11 CVEs total

CVE-2026-100839 8.4 HIGH Contrast before 1.18.0 AML Injection Remote Code Execution
CVE-2026-100833 8.2 HIGH Contrast before 1.23.1 Image Substitution via Policy Generation
CVE-2026-100838 8.1 HIGH Contrast before 1.19.1 CopyFile Policy Symlink Subversion
CVE-2026-100835 7.4 HIGH Contrast before 1.16.0 Remote Attestation Relay Attack
CVE-2025-71425 7.3 HIGH Contrast before 1.8.1 Information Disclosure via Logging
CVE-2025-71423 7.3 HIGH Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVE-2025-71426 7.1 HIGH Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
CVE-2025-71422 5.7 MEDIUM Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
CVE-2026-100836 4.3 MEDIUM Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
CVE-2026-100837 3.7 LOW Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching

IV. Related Vulnerabilities

V. Comments for CVE-2025-71424

No comments yet


Leave a comment