CVE-2026-15791
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
21/07/2026
Última modificación:
30/07/2026
Descripción
*** Pendiente de traducción *** A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.
Impacto
Puntuación base 4.0
1.80
Gravedad 4.0
BAJA
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:* | 0.31.2 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



