Back to CVE List

CVE-2026-15793

Vulnerability Description

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-88
Source
NVD
Vendor
moby
Product
BuildKit

External References

Discussion (0)

Add Comment

No comments yet. Be the first!