Command Injection Vulnerability in Moby BuildKit by Docker
CVE-2026-15793

6.5MEDIUM

Key Information:

Vendor

Moby

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-15793?

A command injection vulnerability exists in Moby BuildKit, which allows attackers to exploit the low-level API used by custom frontends or clients. By setting the 'git.checkoutbundle' option to true during the checkout of Git sources, an attacker can execute arbitrary commands on the host if the Git source is compromised. This presents a significant risk, as it can lead to unauthorized access and control of the affected systems.

Affected Version(s)

BuildKit Linux 0.30.0 <= 0.31.1

References

CVSS V4

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhibin Hu of HuaweiCloud
Lei Wang of HuaweiCloud
.