Feed/CVE-2026-15788
CVE-2026-15788HIGHCVSS 7.5

CVE-2026-15788

Published Jul 20, 2026·Updated Aug 5, 2026

NVD Description

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free