CVE-2026-93320

Summary

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

Affected Software

VendorProductVersion RangeStatus
mobyBuildKit0 <= 0.33.0affected

Weaknesses

  • CWE-441: CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')

Workarounds

Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References