Image Manipulation Vulnerability in Moby BuildKit
CVE-2026-93318
7.5HIGH
What is CVE-2026-93318?
A security flaw in Moby BuildKit allows a malicious image to mislead the system by advertising DiffIDs from another image without aligning with the actual layer contents. This can lead to compromised builds if a BuildKit daemon processes the malicious image, potentially allowing an attacker to execute their code within a victim build. By mounting an attacker-controlled layer, sensitive data such as build secrets may be exposed, and it may interfere with build processes by altering output artifacts or causing hangs. This vulnerability affects users employing snapshotters in their build environments.
Affected Version(s)
BuildKit 0 < 0.33.1
References
CVSS V4
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kohei Tokunaga (https://github.com/ktock)
