Directory Traversal Vulnerability in BuildKit by Moby
CVE-2026-15791

3.3LOW

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-15791?

A vulnerability in Moby's BuildKit allows an attacker to exploit a crafted message in the low-level build API, enabling them to potentially delete files within the actual host's /tmp directory. This occurs when actions intended for the build container's root filesystem are improperly executed, leading to unauthorized access and manipulation of the host system's file structure.

Affected Version(s)

BuildKit Linux 0.10.0 < 0.31.2

References

CVSS V4

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Owais Lone (thesecguy)
.