PT-2026-78681 · Buildkit · Buildkit

CVE-2026-75593

·

Published

2026-08-19

·

Updated

2026-08-25

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BuildKit versions prior to 0.31.2
Description A custom client with valid permissions to access the BuildKit control API can send a specially crafted upload request to the BuildKit daemon. This allows files to escape from the BuildKit-controlled state directory, potentially enabling the client to bypass authentication or other security controls.
Recommendations Update to version 0.31.2.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97035
CVE-2026-75593
GHSA-G2H8-426C-7976

Affected Products

Buildkit