LOWVulnerability

CVE-2026-75593

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

Properties

epss_score
0.0054
cve_id
CVE-2026-75593
published_at
2026-08-19T20:17:23.203
last_modified
2026-09-09T21:15:59.613
epss_percentile
0.43716

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75593 — Ninja Signal Threat Intelligence | Ninja Signal