← Back to CVE search

CVE-2026-64777

container

Description

A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.

CVSS 4.3EPSS 0.232%Risk 0.44
View source
Published
2026-08-20 19:16:57
Affected versions
<1.2.0
Type
Docker image
Last modified
2026-08-27 20:09:53
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N