VYPR
High severity7.5NVD Advisory· Published Jul 21, 2026· Updated Jul 30, 2026

CVE-2026-15793

CVE-2026-15793

Description

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mobyproject:buildkit:*:*:*:*:*:*:*:*range: >=0.30.0,<0.31.2
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.