PT-2026-61984 · Buildkit · Buildkit

·

CVE-2026-15791

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

1.8

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BuildKit (affected versions not specified)
Description A crafted message in the low-level build API allows an attacker to remove the contents of the /tmp directory. This occurs because an action intended to delete files within the build container rootfs can escape and affect the actual host temporary directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15791
GHSA-32PV-7HQ5-QHWQ

Affected Products

Buildkit