Loading market data...
← Back to CVE feed

CVE-2026-15793

UNKNOWN View on NVD ↗

Description

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

Published: Jul 21, 2026 17:17 UTC Modified: Jul 21, 2026 18:27 UTC