CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-75593

unknowncovered by 2 sourcesfirst seen 2026-08-11
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

CSIRTS triage

What
A malicious client can bypass destination directory validation when uploading local sources.
Who is affected
BuildKit instances accepting uploads from untrusted clients.
Urgency
Unknown severity; path traversal during build uploads could allow access to unintended files.
Action
Apply security update for CVE-2026-75593 when available and restrict BuildKit client access if possible.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-75593

Get an email if CVE-2026-75593 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-75593

CVE.org record

Embed the live status

CVE-2026-75593 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-75593 status](https://www.csirts.com/badge/CVE-2026-75593)](https://www.csirts.com/cve/CVE-2026-75593)