Medium severity4.3NVD Advisory· Published Aug 20, 2026· Updated Aug 27, 2026
CVE-2026-64777
CVE-2026-64777
Description
A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=1.2.0
Patches
Vulnerability mechanics
References
1- github.com/apple/container/security/advisories/GHSA-2v2q-4q35-h585nvdVendor AdvisoryMitigation
News mentions
1- Apple Patches Six Vulnerabilities in macOS, watchOS, and Container TechVypr Intelligence · Aug 21, 2026