Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-15793

Опубликовано: 21 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*
Версия от 0.30.0 (включая) до 0.31.2 (исключая)

EPSS

Процентиль: 10%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

CVSS3: 7.5
debian
около 1 месяца назад

BuildKit custom frontends or clients using the raw low-level API can s ...

EPSS

Процентиль: 10%
0.00202
Низкий

7.5 High

CVSS3

Дефекты

CWE-88