CVE-2026-93320mediumCWE-441

CVE-2026-93320: medium-severity vulnerability in moby BuildKit

BuildKit improperly handles special files in build snapshots

Published

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H
Affected products
moby · BuildKit