CVE-2026-93320
6
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H
Summary
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| moby | BuildKit | 0 <= 0.33.0 | affected |
Weaknesses
- CWE-441: CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
Workarounds
Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2
- https://github.com/moby/buildkit/releases/tag/v0.33.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.