Moby BuildKit是Moby团队开源的一款容器镜像构建引擎。 Moby BuildKit 0.31.1之前版本存在输入验证错误漏洞,该漏洞源于自定义前端可在特制构建请求中放置无效的SecurityMode值,executor/oci/spec_linux.go将不支持的值视为非沙箱模式,无需security.insecure授权,导致禁用Seccomp和AppArmor保护。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75593 | 7.2 HIGH | BuildKit: Malicious client can bypass destination directory validation on local sources up |
| CVE-2026-61712 | 2.3 LOW | BuildKit: Possible runtime DoS via unbounded group parsing |
No comments yet