CVE-2026-15791: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in moby BuildKit
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-15791) in moby BuildKit 0.10.0 involves improper limitation of a pathname to a restricted directory (CWE-22). A crafted message sent to the BuildKit low-level build API can exploit this flaw to remove files from the host's /tmp directory by escaping the container root filesystem boundary. The CVSS 4.0 base score is 3.3, indicating low severity, with attack vector local, low complexity, partial impact on integrity and availability, and requiring user interaction without privileges.
Potential Impact
An attacker able to send crafted messages to the BuildKit low-level build API can delete files in the host's /tmp directory. This could disrupt temporary file storage on the host, potentially affecting processes relying on /tmp. The impact is limited to partial integrity and availability loss and requires local access and user interaction.
Mitigation Recommendations
No official patch or remediation level is currently available for this vulnerability. Users should monitor the vendor advisory for updates. Until a fix is released, restrict access to the BuildKit low-level build API to trusted users only to prevent exploitation.
CVE-2026-15791: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in moby BuildKit
Description
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.
CVSS v4.0
Score 3.3low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-15791) in moby BuildKit 0.10.0 involves improper limitation of a pathname to a restricted directory (CWE-22). A crafted message sent to the BuildKit low-level build API can exploit this flaw to remove files from the host's /tmp directory by escaping the container root filesystem boundary. The CVSS 4.0 base score is 3.3, indicating low severity, with attack vector local, low complexity, partial impact on integrity and availability, and requiring user interaction without privileges.
Potential Impact
An attacker able to send crafted messages to the BuildKit low-level build API can delete files in the host's /tmp directory. This could disrupt temporary file storage on the host, potentially affecting processes relying on /tmp. The impact is limited to partial integrity and availability loss and requires local access and user interaction.
Mitigation Recommendations
No official patch or remediation level is currently available for this vulnerability. Users should monitor the vendor advisory for updates. Until a fix is released, restrict access to the BuildKit low-level build API to trusted users only to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Docker
- Date Reserved
- 2026-07-14T19:30:08.561Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5fa1722a4a8d59896d3417
Added to database: 07/21/2026, 16:42:26 UTC
Last enriched: 07/21/2026, 16:57:47 UTC
Last updated: 07/21/2026, 21:11:39 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.