PT-2026-51578 · Daytona · Daytona
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Daytona versions prior to 0.185.0
Description
The daemon's git clone implementation disables TLS certificate verification. When a clone request includes Git credentials, the daemon transmits the HTTP Basic Authorization header to the remote server over a connection with an unvalidated certificate. This occurs in both the go-git and native git CLI code paths. An attacker capable of intercepting clone traffic could use a fraudulent TLS certificate to capture the supplied Git credentials and inject tampered repository content into the sandbox.
Recommendations
Update to version 0.185.0.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Daytona