SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-15793

HIGH · CVSS 7.5 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Custom frontends or clients utilizing BuildKit's low-level API are vulnerable when the git.checkoutbundle option is set to true, allowing potentially malicious Git sources to execute crafted commands on the host system. This vulnerability poses a high risk as it can lead to unauthorized command execution, compromising the integrity of the host environment. Organizations using BuildKit for building applications should prioritize addressing this vulnerability to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15793
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

Related CVEs

Other vulnerabilities affecting the same vendor(s)