VendorsMobyprojectbuildkitany version
Vulnerabilities

Mobyproject Moby Project BuildKit any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-23652
BuildKit possible host system access from mount stub cleaner
Published 2024-01-31 · Modified
10.0EPSS 0.021
CVE-2024-23653
BuildKit interactive containers API does not validate entitlements check
Published 2024-01-31 · Modified
9.8EPSS 0.030
CVE-2026-33747
BuildKit vulnerable to malicious frontend causing file escape outside of storage root
Published 2026-03-27 · Analyzed
9.8EPSS 0.005
CVE-2024-23651
BuildKit possible race condition with accessing subpaths from cache mounts
Published 2024-01-31 · Modified
8.7EPSS 0.008
CVE-2026-33748
BuildKit Git URL subdir component can cause access to restricted files
Published 2026-03-27 · Analyzed
8.2EPSS 0.005
CVE-2026-15789
Malicious client can bypass destination directory validation on local sources upload
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2026-15788
WCOW cache mount source selector resolves NTFS junctions outside of cache root
Published 2026-07-20 · Analyzed
7.5EPSS 0.003
CVE-2026-15791
LLB file operation can be tricked to remove /tmp directory contents
Published 2026-07-21 · Analyzed
7.5EPSS 0.002
CVE-2026-15792
Possible panic when incorrect parameters sent from frontend
Published 2026-07-21 · Analyzed
7.5EPSS 0.002
CVE-2026-15793
Git source checkout from a bundle file could lead to command injection
Published 2026-07-21 · Analyzed
7.5EPSS 0.002
CVE-2023-26054
Credentials inlined to Git URLs could end up in provenance attestation in BuildKit
Published 2023-03-06 · Modified
6.5EPSS 0.010
CVE-2024-23650
BuildKit possible panic when incorrect parameters sent from frontend
Published 2024-01-31 · Modified
5.3EPSS 0.010