CVE-2026-15789
EUVD-2026-4630921.07.2026, 17:17
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mobyproject | buildkit | 𝑥 < 0.31.2 |
𝑥
= Vulnerable software versions