CVE-2026-93320: medium-severity vulnerability in moby BuildKit
BuildKit improperly handles special files in build snapshots
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H
Affected products
moby · BuildKitRelated CVEs — moby BuildKit
In the same product, most dangerous first.
CVE-2026-15788MEDIUMWCOW cache mount source selector resolves NTFS junctions outside of cache rootEPSS 0.4%CVE-2026-15789MEDIUMMalicious client can bypass destination directory validation on local sources uploadEPSS 0.3%CVE-2026-93326MEDIUMCrafted Git build source can bypass certain policy validationEPSS 0.2%CVE-2026-15791LOWLLB file operation can be tricked to remove /tmp directory contentsEPSS 0.2%CVE-2026-15792MEDIUMPossible panic when incorrect parameters sent from frontendEPSS 0.2%CVE-2026-93316HIGHStarting daemon with --cdi-disabled flag can lead to panic on specific buildsEPSS 0.2%