What is CVE-2026-75593?
CVE-2026-75593: A vulnerability in the BuildKit toolkit allows files to escape from the BuildKit-controlled state directory. This affects versions prior to 0.31.2 and can be exploited via a specially crafted upload request from a client. Updating BuildKit to the patched version is strongly recommended to prevent unauthorized file access.
Azərbaycanca: CVE-2026-75593: BuildKit alət dəstində aşkar edilmiş zəiflik BuildKit tərəfindən idarə olunan state qovluğundan fayl qaçırmağa imkan verir. Bu boşluq 0.31.2 versiyasından əvvəlki versiyalara təsir edir və xüsusi hazırlanmış yükləmə sorğusu vasitəsilə baş verə bilər. Təsirə məruz qalan sistemlərdə BuildKit-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of BuildKit are affected by CVE-2026-75593?
This vulnerability affects versions of BuildKit prior to 0.31.2.
What can an attacker achieve by exploiting CVE-2026-75593?
It can allow files to escape from the BuildKit-controlled state directory via a specially crafted upload request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.