CVE-2025-6587
Exposure of system environment variables in Docker Desktop diagnostic logs
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.ย A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.
| CWE | CWE-532 |
| Vendor | docker |
| Product | docker desktop |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 3, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for docker docker desktop
Be the first to know when new unknown vulnerabilities affecting docker docker desktop are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Docker / Docker Desktop
0 < 4.43.0