Two high-severity vulnerabilities in BuildKit could let attackers access or write files outside intended build boundaries. CVE-2026-33747 affects BuildKit versions prior to 0.28.1 and allows a malicious custom frontend to craft API messages that write files outside the BuildKit state directory for the execution context. The issue is exploitable when an untrusted frontend is invoked through #syntax or --build-arg BUILDKIT_SYNTAX; commonly used trusted frontend images such as docker/dockerfile are not affected. The flaw is tracked as CWE-22 and carries a CVSS v3.1 vector of AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
A second flaw, CVE-2026-33748, also patched in BuildKit 0.28.1, stems from improper validation of Git URL fragment subdir components and can expose files outside the checked-out repository root. The impact is limited to files on the same mounted filesystem and affects builds that use Git URLs with a subpath component, particularly where untrusted repository paths may resolve through symlinks. Maintainers fixed both issues in version 0.28.1 and advised users to avoid untrusted frontends, untrusted Dockerfile sources, and untrusted Git repository subdirectory inputs until patched.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
BuildKit version 0.28.1 was identified as the release that fixes CVE-2026-33747 and CVE-2026-33748. The fixes were documented in the associated GitHub security advisory and release notes.
Two vulnerabilities affecting BuildKit versions prior to 0.28.1 were publicly documented: one allowing malicious frontends to write files outside the BuildKit state directory, and another allowing Git URL subdir handling to access files outside the checked-out repository root. Both issues were published with remediation guidance and linked to the same fixed release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.