Executive brief
Moby BuildKit, a tool used for building container images, contains a flaw in its low-level programming interface. An attacker could use a specially crafted message to delete files in the host system's temporary directory instead of the intended container environment. While this could disrupt operations by deleting temporary system files, it requires the use of a custom build frontend and cannot be triggered through standard Dockerfile builds.
Technical details
A path traversal vulnerability (CWE-22) exists in the BuildKit low-level build (LLB) API. The root cause is improper validation of file operation messages, which allows a delete action intended for the build container's rootfs to escape into the host's /tmp directory. Exploitation requires the attacker to use a custom BuildKit frontend to send a crafted LLB message; the vulnerability is not reachable via standard Dockerfile builds. Successful exploitation results in the unauthorized removal of contents within the host's temporary directory. The issue is patched in BuildKit version 0.31.2.
Affected products
- Moby BuildKit >= 0.10.0, < 0.31.2
Timeline
- 2026-07-16: advisory: GitHub Security Advisory published
- 2026-07-21: disclosed: NVD publication date
- 2026-07-16: patched: Fixed in version 0.31.2