Skip to content

Git source checkout from a bundle file could lead to command injection

Moderate
tonistiigi published GHSA-hw3h-2gp9-cxpv Jul 16, 2026

Package

No package listed

Affected versions

v0.30.0 - v0.31.1

Patched versions

v0.31.2+

Description

Impact

BuildKit custom frontends or clients using the raw low-level API can set
git.checkoutbundle=true when checking out Git sources. If the Git source is
malicious, this could lead to a crafted command invocation on the host.

Patches

The issue has been fixed in v0.31.2+.

Workarounds

The issue requires using a custom frontend together with a malicious Git source. Current Dockerfile builds are not affected.

References

Credits

This issue was reported by Zhibin Hu and Lei Wang of HuaweiCloud

Severity

Moderate

CVE ID

CVE-2026-15793

Weaknesses

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string. Learn more on MITRE.

Credits