Image Manipulation Vulnerability in Moby BuildKit
CVE-2026-93318

7.5HIGH

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-93318?

A security flaw in Moby BuildKit allows a malicious image to mislead the system by advertising DiffIDs from another image without aligning with the actual layer contents. This can lead to compromised builds if a BuildKit daemon processes the malicious image, potentially allowing an attacker to execute their code within a victim build. By mounting an attacker-controlled layer, sensitive data such as build secrets may be exposed, and it may interfere with build processes by altering output artifacts or causing hangs. This vulnerability affects users employing snapshotters in their build environments.

Affected Version(s)

BuildKit 0 < 0.33.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kohei Tokunaga (https://github.com/ktock)
.