Executive brief
Apple's container build tool fails to properly validate symlinks during build context file synchronization, allowing a malicious builder peer to read files outside the build directory. An attacker with control over the builder image or BuildKit process could exploit this to disclose sensitive host files if the build context contains symlinks pointing outside its directory tree. This could expose credentials, configuration files, or other sensitive data during the build process.
Technical details
The vulnerability is a path traversal/symlink escape in the BuildFSSync.read() and BuildFSSync.info() functions in Sources/ContainerBuild/BuildFSSync.swift. The host-side code performs lexical (textual) path validation to check if a requested filename is within the build context directory, but does not resolve symlinks before this check. A malicious builder peer can request a symlink by its in-context name, and the host will return the contents of whatever the symlink target resolves to, potentially outside the build context. The exploit requires two preconditions: a compromised or untrusted builder peer (via custom build.image configuration or supply-chain compromise) and a symlink in the build context pointing outside it. The stock builder does not exploit this except in a narrow startup race window. Fixed in container version 1.2.0 by resolving paths before validation.
Affected products
- Apple container <= 1.1.0
Timeline
- 2026-08-12: disclosed: GitHub Security Advisory GHSA-2v2q-4q35-h585 published
- 2026-08-20: advisory: CVE-2026-64777 published on NVD
- 2026-08-12: patched: Fixed in container version 1.2.0