Mobyproject
Mobyproject Buildkit: vulnerabilidades y CVE
Mobyproject Buildkit tiene 12 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses7
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15793 | Alta (7.3) | 0.20% | — | 21 jul 2026 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host. |
| CVE-2026-15792 | Media (6) | 0.24% | — | 21 jul 2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. |
| CVE-2026-15791 | Baja (1.8) | 0.25% | — | 21 jul 2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the… |
| CVE-2026-15789 | Media (6.9) | 0.31% | — | 21 jul 2026 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API… |
| CVE-2026-15788 | Media (5.6) | 0.41% | — | 20 jul 2026 | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured… |
| CVE-2026-33748 | Alta (8.2) | 0.53% | — | 27 mar 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow… |
| CVE-2026-33747 | Crítica (9.8) | 0.58% | — | 27 mar 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API… |
| CVE-2024-23653 | Crítica (9.8) | 3.4% | — | 31 ene 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running… |
| CVE-2024-23652 | Crítica (9.1) | 2.5% | — | 31 ene 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes… |
| CVE-2024-23651 | Alta (7.4) | 0.91% | — | 31 ene 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could… |
| CVE-2024-23650 | Media (5.3) | 1.1% | — | 31 ene 2024 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon… |
| CVE-2023-26054 | Media (6.5) | 1.0% | — | 6 mar 2023 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request that contains a Git URL that contains… |