CVE-2026-15788: Mobyproject Buildkit

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

Affected products

Published 2026-07-20. Last modified 2026-08-05.