File Escape Vulnerability in BuildKit Daemon by Moby
CVE-2026-15789
6.9MEDIUM
What is CVE-2026-15789?
A vulnerability exists within the BuildKit daemon that allows a custom client to construct specific upload requests, potentially enabling files to escape from the designated BuildKit-controlled state directory. Successful exploitation requires the client to have valid permissions to interact with the BuildKit control API, thus posing a risk of unauthorized access and manipulation.
Affected Version(s)
BuildKit Linux 0 < 0.31.2
