BuildKit <=0.31.2 Cache Mount NTFS Junction Remote File Read on WCOW
CVE-2026-15788 Published on July 20, 2026

WCOW cache mount source selector resolves NTFS junctions outside of cache root
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

Vendor Advisory NVD

Weakness Type

What is an insecure temporary file Vulnerability?

The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVE-2026-15788 has been classified to as an insecure temporary file vulnerability or weakness.


Affected Versions

moby BuildKit: