Path traversal in BuildKit - CVE-2026-33747

 

Path traversal in BuildKit - CVE-2026-33747

Published: April 28, 2026


Vulnerability identifier: #VU128396
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33747
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write files outside of the BuildKit state directory.

The vulnerability exists due to improper path restriction in custom BuildKit frontend API message handling when processing a crafted API message from a custom frontend. A remote attacker can craft an API message to write files outside of the BuildKit state directory.

Exploitation requires use of an untrusted custom frontend configured with #syntax or --build-arg BUILDKIT_SYNTAX.


Affected software

BuildKit
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Containers Module
Ubuntu
Fedora
doctl
docker-compose
docker-stable-zsh-completion
docker-stable-bash-completion
docker-stable-debuginfo
docker-stable
docker.io-app (Ubuntu package)

How to mitigate CVE-2026-33747

Install security update from vendor's website.

BuildKit - update to 0.28.1
doctl - addressed in versions 1.154.0-1.fc42, 1.154.0-1.fc43
docker-compose - addressed in versions 5.1.3-1.fc42, 5.1.3-1.fc43, 5.1.3-1.fc44, 5.1.3-1.fc45, 5.1.4-1.fc42, 5.1.4-1.fc43, 5.1.4-1.fc44
docker-stable-zsh-completion - update to 24.0.9_ce-150000.1.42.1
docker-stable-bash-completion - update to 24.0.9_ce-150000.1.42.1
docker-stable-debuginfo - update to 24.0.9_ce-150000.1.42.1
docker-stable - update to 24.0.9_ce-150000.1.42.1
docker.io-app (Ubuntu package) - addressed in versions 26.1.3-0ubuntu1~20.04.1+esm2, 29.1.3-0ubuntu3~22.04.2, 29.1.3-0ubuntu3~24.04.2, 29.1.3-0ubuntu4.1

External References

Related Security Bulletins