๐Ÿ” CVE Alert

CVE-2026-15793

UNKNOWN 0.0

Git source checkout from a bundle file could lead to command injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

CWE CWE-88
Vendor moby
Product buildkit
Published Jul 21, 2026
Last Updated Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for moby buildkit

Be the first to know when new unknown vulnerabilities affecting moby buildkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

moby / BuildKit
0.30.0 โ‰ค 0.31.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/buildkit/security/advisories/GHSA-hw3h-2gp9-cxpv

Credits

Zhibin Hu of HuaweiCloud Lei Wang of HuaweiCloud