PT-2026-80241 · Go · Github.Com/Moby/Buildkit

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Impact

A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers.

Patches

Problem has been fixed in versions v0.31.1+

Workarounds

Only use BuildKit frontends from trusted providers.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-7236-3392-C5C6

Affected Products

Github.Com/Moby/Buildkit