PT-2026-61699 · Buildkit · Buildkit
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
BuildKit (affected versions not specified)
Description
On Windows Container on Windows (WCOW) workers, the cache mount
source= selector fails to detect NTFS directory junctions located within the cache root. This allows an untrusted user to read arbitrary host files that are accessible to the BuildKit daemon process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buildkit