OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-93318

HIGH · CVSS 7.5 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A vulnerability exists in BuildKit that allows a malicious image to advertise DiffIDs from another image while containing different layer contents, potentially leading to the execution of attacker-controlled code in subsequent builds. If a BuildKit daemon processes this malicious image first, it may inadvertently mount the attacker's layer contents in a victim build, compromising build secrets and resources. Organizations using BuildKit, especially those with shared or persistent caches, should prioritize addressing this vulnerability to prevent unauthorized access and manipulation of their build processes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93318
Severity
HIGH
CVSS
7.5
EPSS
0.17%

Original NVD Description

A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build. The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.