CVE Explorer
CVE-2026-33747
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"buildkit","vendor":"moby","versions":[{"status":"affected","version":"< 0.28.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:91e659d2c1e095e03685ec6b771173b04a3ed64cc054a9c166f169e296e9687d · sha256:b8b7cad96ab8c0b3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:91e659d2c1e095e03685ec6b771173b04a3ed64cc054a9c166f169e296e9687d · sha256:b8b7cad96ab8c0b3… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:91e659d2c1e095e03685ec6b771173b04a3ed64cc054a9c166f169e296e9687d · sha256:b8b7cad96ab8c0b3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/moby/buildkit/releases/tag/v0.28.1","tags":["x_refsource_MISC"],"url":"https://github.com/moby/buildkit/releases/tag/v0.28.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:91e659d2c1e095e03685ec6b771173b04a3ed64cc054a9c166f169e296e9687d · sha256:b8b7cad96ab8c0b3… · /containers/cna/references/1
{"name":"https://github.com/moby/buildkit/security/advisories/GHSA-4c29-8rgm-jvjj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/moby/buildkit/security/advisories/GHSA-4c29-8rgm-jvjj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:91e659d2c1e095e03685ec6b771173b04a3ed64cc054a9c166f169e296e9687d · sha256:b8b7cad96ab8c0b3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.