Loading HuntDB...

GHSA-4v98-7qmw-rqr8

GitHub Security Advisory

BuildKit vulnerable to possible host system access from mount stub cleaner

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

### Impact
A malicious BuildKit frontend or Dockerfile using `RUN --mount` could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system.

### Patches
The issue has been fixed in v0.12.5

### Workarounds
Avoid using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing `RUN --mount` feature.

### References

Affected Packages

Go github.com/moby/buildkit
Affected versions: 0 (fixed in 0.12.5)

Related CVEs

Key Information

GHSA ID
GHSA-4v98-7qmw-rqr8
Published
January 31, 2024 10:43 PM
Last Modified
February 1, 2024 5:48 PM
CVSS Score
9.0 /10
Primary Ecosystem
Go
Primary Package
github.com/moby/buildkit
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.