CVE-2026-93320
MEDIUM
6,0
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
441
Unintended Proxy or Intermediary ('Confused Deputy')
DraftCommon Consequences
Security Scopes Affected:
Non-Repudiation
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Hide Activities
Execute Unauthorized Code Or Commands
Applicable Platforms
All platforms may be affected
https://github.com/moby/buildkit/releases/tag/v0.33.1
https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2