github.com/moby/buildkit is vulnerable to Path Traversal
53
Medium Risk
BuildKit does not neutralize traversal sequences in destination paths when handling local source uploads. A custom client with access to the control API can craft an upload request whose destination escapes the BuildKit-controlled state directory. This lets files be written outside the intended directory on the daemon host. The fix validates upload destinations against the state directory.
You are affected if you are using a version that falls within the vulnerable range and you run a BuildKit service that accepts builds from untrusted clients with access to the control API.
github.com/moby/buildkit is vulnerable to Path Traversal in versions 0.0.1 - 0.31.1.
Upgrade the github.com/moby/buildkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant