Executive brief
A security vulnerability exists in the .NET SDK component used for building container images. A local attacker on a shared build machine could inject malicious resources into container images being built by other users. This could lead to the deployment of compromised software or unauthorized access to sensitive data within those containers.
Technical details
A tampering vulnerability (CWE-59: Improper Link Resolution Before File Access) exists in the Microsoft.NET.Build.Containers package within the .NET SDK. The flaw occurs during the container image build process when the SDK fails to properly resolve links before file access. An attacker with local access and low privileges can exploit this by creating symbolic links to inject malicious resources into container images being built by other users on the same system. This requires the attacker to time their actions with a concurrent build process (High Complexity). Patches are available in .NET SDK versions 8.0.29, 9.0.18, and 10.0.10.
Affected products
- Microsoft Microsoft.NET.Build.Containers >= 10.0.0, <= 10.0.9
- Microsoft Microsoft.NET.Build.Containers >= 9.0.0, <= 9.0.17
- Microsoft Microsoft.NET.Build.Containers >= 8.0.0, <= 8.0.28
Timeline
- 2026-07-14: advisory: Initial advisory published by Microsoft
- 2026-07-14: patched: Patched versions released for .NET 8, 9, and 10
- 2026-07-21: disclosed: GitHub Advisory published
References
- https://github.com/dotnet/sdk/security/advisories/GHSA-55jh-fwmh-39m4
- https://github.com/dotnet/announcements/issues/415
- https://github.com/dotnet/sdk/issues/55274
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50526
- https://api.github.com/repos/dotnet/sdk/security-advisories/GHSA-55jh-fwmh-39m4