PT-2026-92018 · Docker · Docker Sandboxes
CVSS v4.0
9.4
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Docker Sandboxes versions 0.28.0 through 0.41.9
Docker Desktop (affected versions not specified)
Description
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink to escape the shared workspace, allowing them to read or modify arbitrary host files with the privileges of the VMM user. This guest-to-host filesystem escape could potentially lead to host code execution. The issue is particularly critical for AI-agent workflows where untrusted code is executed within sandboxes.
Recommendations
Update Docker Sandboxes to version 0.42.0 or later.
Update Docker Desktop to version 4.88.0 or later.
Minimize read-write host mounts.
Use clone mode where appropriate.
Keep credentials outside shared workspaces.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker Sandboxes