CVE-2026-33747Disclosure(mobyproject / buildkit)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • buildkit

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-27); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
buildkit

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-26: 1Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 203-2603-2703-28
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-273
Disclosure2General1
2026-03-281
Disclosure1
Full discourse5 posts
  • Paweł Gronowski@grono_dev
    Disclosure

    CVE-2026-33747 / GHSA-3c29-8rgm-jvjj An untrusted BuildKit frontend could write files outside BuildKit’s state directory. Relevant for custom/untrusted frontends in build systems

    Post summary

    A vulnerability in untrusted BuildKit frontends enables them to write files outside the state directory, exposing potential file‑write issues.

    1000050
    10 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33747 - High BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the fron... https://www.thehackerwire.com/vulnerability/CVE-2026-33747/ https://t.co/wghh5MmV1U

    Post summary

    Tweet announces CVE‑2026‑33747, a high‑severity vulnerability in BuildKit affecting versions before 0.28.1, and directs readers to an external article for further details.

    0000038
    163 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33747 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom Bu… https://www.cve.org/CVERecord?id=CVE-2026-33747

    Post summary

    The snippet references CVE-2026-33747 in BuildKit but offers no substantive vulnerability details, remediation, or exploitation information.

    0000093
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33747 📊 Severity: 8.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33747 #CVE-2026-33747 #CVE #High #CyberSecurity #InfoSec https://t.co/eF10VYaucT

    Post summary

    The tweet announces CVE-2026-33747, noting its 8.4 CVSS score, high risk level, and unspecified product impact while providing a link to the NVD for details.

    0000026
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33747 - BuildKit vulnerable to malicious frontend causing file escape outside of storage root Intel Report: https://ift.tt/wStT6mi

    Post summary

    CVE-2026-33747 is disclosed as a BuildKit vulnerability that allows a malicious frontend to escape the storage root, with details linked in an intel report.

    0000034
    284 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmobyprojectbuildkit---

Explore more