Executive brief
Moby BuildKit is a toolkit used to convert source code into container images, such as those used by Docker. A security flaw allows a user with permission to start builds to bypass directory restrictions and place files outside of the intended storage area on the host system. This could lead to unauthorized file modification or system instability if an attacker uses a custom-made client to interact with the BuildKit service.
Technical details
A path traversal vulnerability (CWE-22) exists in the BuildKit daemon's handling of local source upload requests. By crafting a malicious upload request using a custom client, an attacker can bypass destination directory validation to write files outside of the BuildKit-controlled state directory. Exploitation requires the attacker to have valid permissions to access the BuildKit control API. The vulnerability is addressed in BuildKit version 0.31.2. Users are advised to upgrade or restrict API access to trusted clients like Docker Buildx or buildctl.
Affected products
- Moby BuildKit < 0.31.2
Timeline
- 2026-07-16: advisory: GitHub Security Advisory published by Moby project
- 2026-07-21: disclosed: CVE-2026-15789 published to NVD
- 2026-07-21: patched: Fix released in version 0.31.2