A FROM line is a trust decision. Builds that pull an unpinned base image by a mutable tag inherit whatever that tag points to at build time. An attacker poisons the base: typosquatting a public name close to a popular one, hijacking an abandoned namespace, or compromising a shared internal base image that many teams build on.
# Unpinned base: resolves to whatever :latest points to at build time
FROM company/base:latest
# Pinned by digest resists poisoning
FROM company/base@sha256:<digest>
Exploitation notes#
- The leverage is fan-out: one poisoned shared base image compromises every downstream image and deployment that rebuilds.
- Typosquats target common names (one character off, a different registry namespace) and rely on a typo in a Dockerfile or CI config.
- Pinning by digest defeats tag mutation, so unpinned
FROMlines are the targets to look for.