PT-2026-78681 · Buildkit · Buildkit
CVE-2026-75593
·
Published
2026-08-19
·
Updated
2026-08-25
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
BuildKit versions prior to 0.31.2
Description
A custom client with valid permissions to access the BuildKit control API can send a specially crafted upload request to the BuildKit daemon. This allows files to escape from the BuildKit-controlled state directory, potentially enabling the client to bypass authentication or other security controls.
Recommendations
Update to version 0.31.2.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buildkit