# CVE-2025-59378

## Summary

- **CVE ID:** CVE-2025-59378
- **Severity:** MEDIUM
- **CVSS Score:** 5.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **CWE:** CWE-669
- **Published:** Sep 15, 2025
- **Last Modified:** Mar 13, 2026

## Description

In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).

## Affected Products

- GNU — Guix (0)

## References

- [CNA](https://guix.gnu.org/en/blog/2025/privilege-escalation-vulnerability-2025-2/)
- [CNA](https://codeberg.org/guix/guix/commit/1618ca7aa2ee8b6519ee9fd0b965e15eca2bfe45)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._