CVE-2026-75593
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.
CSIRTS triage
- What
- A malicious client can bypass destination directory validation when uploading local sources.
- Who is affected
- BuildKit instances accepting uploads from untrusted clients.
- Urgency
- Unknown severity; path traversal during build uploads could allow access to unintended files.
- Action
- Apply security update for CVE-2026-75593 when available and restrict BuildKit client access if possible.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-75593
Get an email if CVE-2026-75593 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-75593)