BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
Exploitability
AV:NAC:LAT:PPR:LUI:AVulnerable System
VC:HVI:HVA:HSubsequent System
SC:NSI:NSA:N6.5/CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NOther