Vulnerability Details CVE-2026-15793
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 14.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-15793
-
cpe:2.3:a:mobyproject:buildkit:0.30.0
-
cpe:2.3:a:mobyproject:buildkit:0.31.0
-
cpe:2.3:a:mobyproject:buildkit:0.31.1