Mobyproject
- 5
- vulnérabilités suivies
- 21 juillet 2026
- dernière publication
cve
Veille des vulnérabilités
identifiantvulnérabilitésévéritépublié
CVE-2026-15789A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.Mobyproject Buildkit Élevée CVSS 7.5 CVE-2026-15791A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.Mobyproject Buildkit Élevée CVSS 7.5 CVE-2026-15792A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.Mobyproject Buildkit Élevée CVSS 7.5 CVE-2026-15793BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.Mobyproject Buildkit Élevée CVSS 7.3 CVE-2026-15788BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.Mobyproject Buildkit Élevée CVSS 7.5