CVE-2024-23650: Mobyproject Buildkit
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.
Affected products
- Mobyproject Buildkit: before 0.12.5 (fixed in 0.12.5)
Published 2024-01-31. Last modified 2026-06-17.