Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-15791

Опубликовано: 21 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
Версия до 0.31.2 (исключая)

EPSS

Процентиль: 17%
0.00249
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.

CVSS3: 7.5
debian
около 1 месяца назад

A crafted message in the BuildKit low-level build API can be used to r ...

EPSS

Процентиль: 17%
0.00249
Низкий

7.5 High

CVSS3

Дефекты

CWE-22