Feed/CVE-2026-15789
CVE-2026-15789HIGHCVSS 7.5

CVE-2026-15789

Published Jul 21, 2026·Updated Jul 30, 2026

NVD Description

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free