Status
Impact
CVE-2025-52881 is resolved in version v1.13.0 of the dependency github.com/opencontainers/selinux. However, that version of the dependency depends on v0.6.0 of github.com/cyphar/filepath-securejoin, which introduced breaking changes (the removal of some deprecated functions). undock also depends on github.com/containers/storage, the latest version of which still relies on some of the removed functions. It's not possible to bump selinux to remediate this CVE until the storage dependency is compatible with the latest version of filepath-securejoin
Status