๐Ÿ” CVE Alert

CVE-2026-15789

UNKNOWN 0.0

Malicious client can bypass destination directory validation on local sources upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

CWE CWE-22
Vendor moby
Product buildkit
Published Jul 21, 2026
Last Updated Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for moby buildkit

Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

moby / BuildKit
0 < 0.31.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976

Credits

Kris Kennaway (KrisKennawayDD) of Datadog