PT-2026-61699 · Buildkit · Buildkit

·

CVE-2026-15788

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

5.6

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BuildKit (affected versions not specified)
Description On Windows Container on Windows (WCOW) workers, the cache mount source= selector fails to detect NTFS directory junctions located within the cache root. This allows an untrusted user to read arbitrary host files that are accessible to the BuildKit daemon process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15788

Affected Products

Buildkit