NVD disclosure day

Published threat advisories for December 2, 2025

CVE advisoryCRITICAL

CVE-2025-13828

Composer Package Installation Privilege Escalation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A non-privileged user can install arbitrary packages, potentially executing malicious code and escalating privileges on systems that use composer for package management, even if composer-based updates are disabled. This could allow a low-privileged user to obtain higher privileges on the platform.

CVE advisoryCRITICAL

CVE-2025-59703

Entrust nShield Physical Tamper F14 Attack Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Entrust nShield hardware security modules are vulnerable to a physical tamper attack that allows an attacker with direct access to bypass tamper evidence and access internal components. This could potentially compromise cryptographic operations and sensitive data if the device is reachable by a physically proximate att

CVE advisoryCRITICAL

CVE-2025-59693

Entrust nShield Chassis Debug Access Vulnerability F02.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Entrust nShield devices allows a physically proximate attacker to bypass tamper labels, open the chassis, and access the JTAG connector to gain debug access and escalate privileges. This could compromise sensitive hardware functions and lead to unauthorized system control.