Command Injection Vulnerability in Moby BuildKit by Docker
CVE-2026-15793
6.5MEDIUM
What is CVE-2026-15793?
A command injection vulnerability exists in Moby BuildKit, which allows attackers to exploit the low-level API used by custom frontends or clients. By setting the 'git.checkoutbundle' option to true during the checkout of Git sources, an attacker can execute arbitrary commands on the host if the Git source is compromised. This presents a significant risk, as it can lead to unauthorized access and control of the affected systems.
Affected Version(s)
BuildKit Linux 0.30.0 <= 0.31.1
References
CVSS V4
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zhibin Hu of HuaweiCloud
Lei Wang of HuaweiCloud
