PT-2026-50824 · Daytona · Daytona

·

CVE-2026-54319

·

Published

2026-06-18

·

Updated

2026-07-30

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Daytona versions prior to 0.186
Description A sandbox volume reference volumeId (which may also be a volume name) was forwarded to the runner and used to build the host bind-mount source path without confinement. A reference containing path-traversal sequences—characters used to access files and directories outside the current working directory—could potentially resolve the mount source outside the intended per-volume base directory. If reachable, an authenticated user could cause the runner to bind-mount an unintended host path into their sandbox, potentially allowing read and write access to other tenants' volume data.
Recommendations Update to version 0.186 or later.

Exploit

Fix

Path traversal

Improper Privilege Management

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54319
GHSA-FJV8-J4P5-CR9M
GO-2026-5367
OPENSUSE-SU-2026:21483-1

Affected Products

Daytona