PT-2026-95706 · Unknown · Microsandbox
CVE-2026-61670
·
Published
2026-09-18
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
microsandbox versions prior to 0.5.10
Description
The software serializes
NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repeated --env arguments within sdk/rust/lib/runtime/spawn.rs and crates/cli/lib/sandbox cmd.rs. Local users or co-resident processes can read these secrets via the host process table, such as /proc process command lines on Linux and process listings on Linux and macOS, for the duration of the sandbox. This can lead to the disclosure of host-side API keys, tokens, and environment secrets on shared hosts, CI runners, and developer systems without requiring code execution inside the sandbox or access to the spawning user's session.Recommendations
Update to version 0.5.10.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microsandbox