PT-2026-80241 · Go · Github.Com/Moby/Buildkit
Published
2026-08-19
·
Updated
2026-08-19
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Impact
A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the
security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers.Patches
Problem has been fixed in versions v0.31.1+
Workarounds
Only use BuildKit frontends from trusted providers.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github.Com/Moby/Buildkit