# CVE-2025-62161

## Summary

- **CVE ID:** CVE-2025-62161
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-363, CWE-61
- **Published:** Nov 5, 2025
- **Last Modified:** Mar 13, 2026

## Description

Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape when youki utilizes bind mounting the container's /dev/null as a file mask. This issue is fixed in version 0.5.7.

## Affected Products

- youki-dev — youki (< 0.5.7)

## References

- [CNA](https://github.com/youki-dev/youki/security/advisories/GHSA-4g74-7cff-xcv8)
- [CNA](https://github.com/youki-dev/youki/commit/5886c91073b9be748bd8d5aed49c4a820548030a)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 15.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._