BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
References
| Link | Resource |
|---|---|
| https://github.com/moby/buildkit/security/advisories/GHSA-hw3h-2gp9-cxpv | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-21 17:17
Updated : 2026-07-30 15:33
NVD link : CVE-2026-15793
Mitre link : CVE-2026-15793
CVE.ORG link : CVE-2026-15793
JSON object : View
Products Affected
mobyproject
- buildkit
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
