GPU VulnDB

Database/Container, Kubernetes & orchestration

Docker Buildx Bake: untrusted Bake definition reads files outside the project without approval

CVSS 6.9CVE-2026-103433Container, Kubernetes & orchestrationcurated

Impact

Bake fails to request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable client-side file through a pathless secret whose ID is treated as a pathname, or consume a local OCI image layout outside the project because entitlement validation checks a different representation of the path than the one that gets used. On a CI runner or an operator workstation that builds container images for a GPU fleet, that means a pull-request-supplied Bake file can read registry credentials, kubeconfigs or cloud tokens off the build host without the confirmation prompt that is supposed to gate it. Only users who run untrusted Bake definitions are affected.

Who can reach it

Anyone who can supply the Bake definition a user or CI job then builds - typically a repository contributor. Requires the victim to run the build; no privileges on the host are needed.

What to do

Upgrade Docker Buildx to v0.37.2. Until then, do not run bake on definitions from untrusted sources, and run builds that must handle untrusted definitions on a throwaway runner with no credentials on disk.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.