PT-2026-28525 · Buildkit+3 · Buildkit+3
1Seal
·
Published
2026-03-26
·
Updated
2026-05-18
·
CVE-2026-33747
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BuildKit versions prior to 0.28.1
Description
BuildKit is a toolkit for converting source code to build artifacts. When using a custom BuildKit frontend, a malicious frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. This issue requires using an untrusted BuildKit frontend set with
#syntax or --build-arg BUILDKIT SYNTAX. Using these options with a well-known frontend image like docker/dockerfile is not affected. The API message crafted by the frontend can lead to file escape outside of the storage root.Recommendations
Versions prior to 0.28.1 should be updated to version 0.28.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buildkit
Linuxmint
Red Os
Ubuntu