System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. 
A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 03 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 03 Jul 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection. | |
| Title | Exposure of system environment variables in Docker Desktop diagnostic logs | |
| Weaknesses | CWE-532 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Docker
Published: 2025-07-03T10:03:27.155Z
Updated: 2025-07-04T03:55:30.300Z
Reserved: 2025-06-24T20:47:44.847Z
Link: CVE-2025-6587
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-07-03T13:19:50.770Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-07-03T10:15:37.773
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-6587
 Redhat
                        Redhat
                    No data.