CVE-2026-15788: Mobyproject Buildkit
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.
Affected products
- Mobyproject Buildkit: before 0.31.2 (fixed in 0.31.2)
Published 2026-07-20. Last modified 2026-08-05.