๐Ÿ” CVE Alert

CVE-2026-75593

UNKNOWN 0.0

BuildKit: Malicious client can bypass destination directory validation on local sources upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

CWE CWE-22
Vendor moby
Product buildkit
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for moby buildkit

Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

moby / buildkit
< 0.31.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976 github.com: https://github.com/moby/buildkit/releases/tag/v0.31.2