CVE-2026-93320 MEDIUM

CVE-2026-93320: BuildKit improperly handles special files in build snapshots

Vendor Moby
Product BuildKit
Weakness CWE-441
Published October 5, 2026
Last update October 5, 2026

CVSS base score

6.0/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H

What the vulnerability does

01Description

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

Key dates

02Disclosure timeline

October 5, 2026 CVE published