PT-2026-50824 · Daytona · Daytona
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Daytona versions prior to 0.186
Description
A sandbox volume reference
volumeId (which may also be a volume name) was forwarded to the runner and used to build the host bind-mount source path without confinement. A reference containing path-traversal sequences—characters used to access files and directories outside the current working directory—could potentially resolve the mount source outside the intended per-volume base directory. If reachable, an authenticated user could cause the runner to bind-mount an unintended host path into their sandbox, potentially allowing read and write access to other tenants' volume data.Recommendations
Update to version 0.186 or later.
Exploit
Fix
Path traversal
Improper Privilege Management
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Daytona