← Vulnerability feed

Vulnerability record · CVE-2023-26054 · published 6 March 2023

CVE-2023-26054: Mobyproject buildkit information exposure vulnerability

Mobyproject · Buildkit

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways: 1) Invoking build directly from a URL with credentials. 2) If the client sends additional version control system (VCS) info hint parameters on builds from a local source. Usually, that would mean reading the origin URL from `.git/config` file. When a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in `BuildInfo` structure that is a predecessor of Provenance attestations. Previous versions are not vulnerable. This bug has been fixed in v0.11.4. Users are advised to upgrade. Users unable to upgrade may disable VCS info hints by setting `BUILDX_GIT_INFO=0`. `buildctl` does not set VCS hints based on `.git` directory, and values would need to be passed manually with `--opt`.

6.5 CVSS 3.1 Medium EPSS 1.0% · top 37.8% CWE-200 · Information exposure
6.5CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In affected versions when the user sends a build request that contains a Git URL that contains credentials and the build creates a provenance attestation describing that build, these credentials could be visible from the provenance attestation. Git URL can be passed in two ways: 1) Invoking build directly from a URL with credentials. 2) If the client sends additional version control system (VCS) info hint parameters on builds from a local source. Usually, that would mean reading the origin URL from `.git/config` file. When a build is performed under specific conditions where credentials were passed to BuildKit they may be visible to everyone who has access to provenance attestation. Provenance attestations and VCS info hints were added in version v0.11.0. Previous versions are not vulnerable. In v0.10, when building directly from Git URL, the same URL could be visible in `BuildInfo` structure that is a predecessor of Provenance attestations. Previous versions are not vulnerable. This bug has been fixed in v0.11.4. Users are advised to upgrade. Users unable to upgrade may disable VCS info hints by setting `BUILDX_GIT_INFO=0`. `buildctl` does not set VCS hints based on `.git` directory, and values would need to be passed manually with `--opt`.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26054 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-33747Mobyproject buildkit path traversal vulnerabilityBuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when …EPSS 0.58%9.8CVE-2024-23653Mobyproject buildkit incorrect authorization vulnerabilityBuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running contain…EPSS 3.0%9.1CVE-2024-23652Mobyproject buildkit path traversal vulnerabilityBuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend …EPSS 2.1%8.2CVE-2026-33748Mobyproject buildkit path traversal vulnerabilityBuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insuf…EPSS 0.53%7.4CVE-2024-23651Mobyproject buildkit race condition vulnerabilityBuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps runn…EPSS 0.79%7.3CVE-2026-15793Mobyproject buildkit argument injection vulnerabilityBuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is …EPSS 0.35%6.9CVE-2026-15789Mobyproject buildkit path traversal vulnerabilityA custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The cli…EPSS 0.31%6.0CVE-2026-15792Mobyproject buildkit improper input validation vulnerabilityA malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2023-26054), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.