Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-15789

Опубликовано: 21 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
Версия до 0.31.2 (исключая)

EPSS

Процентиль: 24%
0.00314
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
debian
около 1 месяца назад

A custom client can produce such an upload request to the BuildKit dae ...

EPSS

Процентиль: 24%
0.00314
Низкий

7.5 High

CVSS3

Дефекты

CWE-22