BuildKit <=0.31.2 Cache Mount NTFS Junction Remote File Read on WCOW
CVE-2026-15788 Published on July 20, 2026
WCOW cache mount source selector resolves NTFS junctions outside of cache root
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-15788 has been classified to as an insecure temporary file vulnerability or weakness.
Affected Versions
moby BuildKit:- Before 0.31.2 is affected.