PT-2026-51578 · Daytona · Daytona

·

CVE-2026-54323

·

Published

2026-06-23

·

Updated

2026-06-24

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Daytona versions prior to 0.185.0
Description The daemon's git clone implementation disables TLS certificate verification. When a clone request includes Git credentials, the daemon transmits the HTTP Basic Authorization header to the remote server over a connection with an unvalidated certificate. This occurs in both the go-git and native git CLI code paths. An attacker capable of intercepting clone traffic could use a fraudulent TLS certificate to capture the supplied Git credentials and inject tampered repository content into the sandbox.
Recommendations Update to version 0.185.0.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54323
GHSA-375H-72G4-HC9C

Affected Products

Daytona