Vulnerabilities
Vulnerable Software
Mobyproject:  >> Buildkit  >> 0.29.0  Security Vulnerabilities
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
CVSS Score
6.0
EPSS Score
0.002
Published
2026-07-21
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
CVSS Score
6.9
EPSS Score
0.003
Published
2026-07-21
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.
CVSS Score
1.8
EPSS Score
0.002
Published
2026-07-21
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.
CVSS Score
5.6
EPSS Score
0.003
Published
2026-07-20


Contact Us

Shodan ® - All rights reserved