Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-15793

Опубликовано: 21 июл. 2026
Источник: debian
EPSS Низкий

Описание

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-moby-buildkititppackage

EPSS

Процентиль: 10%
0.00202
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

CVSS3: 7.5
nvd
около 1 месяца назад

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

EPSS

Процентиль: 10%
0.00202
Низкий
Уязвимость CVE-2026-15793