Skip to main content
Vulnerability Database/CVE-2025-71424

CVE-2025-71424: Contrast Runtime Path Traversal Vulnerability

CVE-2025-71424 is a path traversal vulnerability in Contrast runtime for confidential containers on Kubernetes that allows untrusted hosts to write arbitrary files. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-71424 Overview

CVE-2025-71424 affects Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, in versions up to and including 1.9.0. The flaw stems from how containerd handles the VOLUME directive in a Dockerfile when Kubernetes does not provide a corresponding mount. On bare-metal Contrast deployments, an untrusted host can write arbitrary file trees below the volume mount point inside the confidential container. This compromises the integrity of a directory typically important to the application's core functionality. Azure Kubernetes Service (AKS) deployments are not affected. Version 1.9.1 fixes the issue by disallowing this configuration in contrast generate.

Critical Impact

An untrusted host adjacent to a bare-metal Contrast deployment can inject arbitrary files into volume paths inside confidential containers, breaking the integrity guarantees of the confidential computing boundary.

Affected Products

  • Edgeless Systems Contrast versions <= 1.9.0 (bare-metal deployments)
  • Container images declaring at least one VOLUME directive without a matching Kubernetes mount
  • Kata agent integrations relying on containerd's volume mount injection

Discovery Timeline

  • 2026-09-27 - CVE-2025-71424 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2025-71424

Vulnerability Analysis

Contrast provides a runtime for confidential containers on Kubernetes, where the guest workload is intended to be isolated from the untrusted host. The vulnerability is categorized under [CWE-693: Protection Mechanism Failure] because the confidential container's integrity boundary is bypassed through a legitimate container runtime feature.

The VOLUME directive in a Dockerfile, exposed as config.volumes in the OCI image configuration, is advisory and is not handled specially by Kubernetes. However, containerd adds a mount point for each declared volume when Kubernetes does not define one at that path. To satisfy this mount, the runtime must be able to push arbitrary data to the Kata agent inside the confidential VM.

On affected bare-metal deployments, this capability allows the untrusted host to deliver attacker-controlled file trees into the confidential container at the volume path. Applications that rely on the contents of that directory, such as configuration, state, or data directories, can be subverted at startup.

Root Cause

The root cause is that Contrast policy, prior to 1.9.1, did not reject image configurations containing VOLUME directives without matching Kubernetes mounts. The policy allowed the host-mediated mount setup required by containerd, exposing a write primitive into the guest.

Attack Vector

An attacker with control of the untrusted host or the Kubernetes control plane adjacent to the confidential node writes arbitrary file content into the volume mount path before or during container startup. Exploitation requires that the deployed image declare at least one VOLUME and that no Kubernetes mount exists at that path. No user interaction is required, and the attack is local to the deployment network.

No verified public proof-of-concept code is available. See the GitHub Security Advisory GHSA-phhq-63jg-fp7r for upstream technical details.

Detection Methods for CVE-2025-71424

Indicators of Compromise

  • Unexpected files or directory trees appearing beneath paths declared by VOLUME in the container image at process start
  • Container application logs showing altered configuration, state files, or injected data at paths matching the image's declared volumes
  • Contrast policy generation artifacts produced by a contrast CLI version prior to 1.9.1

Detection Strategies

  • Inventory all container images deployed on bare-metal Contrast nodes and enumerate images that include a VOLUME directive in their Dockerfile or OCI config.volumes field
  • Compare each declared image volume against the Kubernetes volumeMounts for the pod to identify unmatched volume paths
  • Audit Contrast runtime versions across the fleet and flag any node running <= 1.9.0

Monitoring Recommendations

  • Enable file integrity monitoring inside confidential workloads for directories matching image VOLUME paths
  • Alert on deployments created or updated with Contrast CLI versions earlier than 1.9.1
  • Log and review admission events for pods targeting bare-metal confidential nodes

How to Mitigate CVE-2025-71424

Immediate Actions Required

  • Upgrade Contrast to version 1.9.1 or later on all bare-metal deployments
  • Regenerate deployment policies with contrast generate from the patched CLI so that unsafe volume configurations are rejected
  • Review images for stray VOLUME directives and remove them from Dockerfiles where not required

Patch Information

Edgeless Systems released Contrast 1.9.1, which fixes the issue by disallowing images with unmatched VOLUME directives in contrast generate. Full details are published in the GitHub Security Advisory GHSA-phhq-63jg-fp7r and the VulnCheck Advisory for Edgeless Systems Contrast.

Workarounds

  • For every image VOLUME path, define a corresponding Kubernetes volumeMount backed by a trusted source such as an in-guest emptyDir or secret so containerd does not request a host-mediated mount
  • Rebuild application images without VOLUME directives when the directory does not need to be externally mountable
  • Restrict bare-metal confidential container deployments to AKS environments until patching is complete, as AKS deployments are not affected

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.