Vulnerability Report: GO-2026-4610
- CVE-2025-15558, GHSA-p436-gjf2-799p
- Affects: github.com/docker/cli, github.com/docker/compose, and 2 more
- Published: Mar 10, 2026
Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli
For detailed information about this vulnerability, visit https://github.com/docker/cli/security/advisories/GHSA-p436-gjf2-799p.
Affected Packages
-
PathGo VersionsCustom Versions*Symbols
-
before v29.2.0+incompatible-
1 unexported affected symbols
- defaultSystemPluginDirs
Affected Modules
-
PathGo VersionsCustom Versions*
-
all versions, no known fixed-
-
all versions, no known fixed-
-
before v5.1.0-
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck. (See this note on versions for more details.)
Aliases
References
- https://github.com/docker/cli/security/advisories/GHSA-p436-gjf2-799p
- https://github.com/docker/cli/commit/13759330b1f7e7cb0d67047ea42c5482548ba7fa
- https://github.com/docker/cli/pull/6713
- https://github.com/docker/compose/pull/12300
- https://docs.docker.com/desktop/release-notes
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-28304
- https://vuln.go.dev/ID/GO-2026-4610.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.