CyberRota Analysis
AI-GeneratedCustom frontends or clients utilizing BuildKit's low-level API are vulnerable when the git.checkoutbundle option is set to true, allowing potentially malicious Git sources to execute crafted commands on the host system. This vulnerability poses a high risk as it can lead to unauthorized command execution, compromising the integrity of the host environment. Organizations using BuildKit for building applications should prioritize addressing this vulnerability to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
Related CVEs
Other vulnerabilities affecting the same vendor(s)