CVE-2026-33748High· 7.5▾ TwilightBuildKit Git URL subdir component can cause access to restricted files
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
Insufficient validation of Git URL fragment subdir components (<url>#<ref>:<subdir>, docs) may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem.
The issue has been fixed in version v0.28.1
The issue affects only builds that use Git URLs with a subpath component. Avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
github.com/moby/buildkit < 0.28.1Upgrade to a patched release:
github.com/moby/buildkit 0.28.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-23652Critical· 10.0BuildKit vulnerable to possible host system access from mount stub cleaner
CVE-2026-61711MediumBuildKit: Custom frontend could bypass Seccomp/AppArmor
CVE-2026-61712LowBuildKit has a possible runtime DoS via unbounded group parsing
CVE-2020-27534Medium· 5.3Path Traversal in Moby builder
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities