Impact
The vulnerability arises when a build definition contains a specially crafted Git source step, causing BuildKit to treat the repository as originating from a different URL during the clone process. This enables an attacker to supply code from an unintended source while the system accepts the provided URL as legitimate. The issue only affects validation that relies on the remote URL; checks based on commit SHA, commit data, or signatures remain effective. The weakness is identified as CWE-180.
Affected Systems
Moby BuildKit is the affected product. The specific bug is noted in the release around v0.33.1 and occurs when builds execute optional Build policies that apply Git source rules based solely on the repository URL. Any deployment of BuildKit that utilizes such policies is potentially impacted.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate risk. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog, so current exploitation likelihood is uncertain. The likely attack vector is an attacker able to inject a malicious build definition into a CI pipeline or a build server that trusts user‑supplied definitions. The flaw requires the specific configuration of URL‑based Git source rules; stricter validations that check commit SHA or signatures remain effective. Exploitation therefore requires both a vulnerable BuildKit installation and authorisation to supply build definitions, making the risk contingent on access controls.
OpenCVE Enrichment