Back

CRITICAL

BuildKit vulnerable to malicious frontend causing file escape outside of storage root

Published Mar 27, 2026

Description

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

Affected products

Remediation

Red Hat mitigation

To mitigate this vulnerability, avoid using untrusted BuildKit frontends. Restrict the use of custom BuildKit frontends to only those from verified and trusted sources. Do not specify untrusted frontends via `#syntax` or `--build-arg BUILDKIT_SYNTAX`.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Mar 27, 2026
Updated Mar 27, 2026
Reserved Mar 23, 2026

CISA Vulnrichment

Updated Mar 27, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 27, 2026
Bugzilla 2452076

ENISA EUVD

Assigner GitHub_M
Published Mar 27, 2026
Updated Mar 27, 2026