CVE-2025-67860Low· 3.8▾ SunlitNeuVector scanner insecurely handles passwords as command arguments
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.09%
A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users. This may allow unauthorized access to registries or the NeuVector controller, potentially enabling image manipulation, information disclosure, or further lateral movement within the environment.
Important:
Please consult the associated MITRE ATT&CK – Technique – Credential Access and Unsecured Credentials for further information about this category of attack.
Patched versions include release v4.072 and above.
Starting from version v4.072, the scanner monitor process does not pass credentials to the scanner anymore. Instead, scanner process gets credentials information from environment variables, preventing them from being exposed through /proc/*/cmdline.
There is no workaround for this issue. Users are recommended to upgrade, as soon as possible, to a version of NeuVector scanner that contains the fix.
If you have any questions or comments about this advisory:
github.com/neuvector/scanner >= 4.0, < 4.072Upgrade to a patched release:
github.com/neuvector/scanner 4.072Connected by shared product, vendor, weakness, or advisory.