CVE-2026-33747: BuildKit's Malicious frontend can cause file escape outside of storage root
(updated )
When using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33747 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →