PT-2026-95706 · Unknown · Microsandbox

CVE-2026-61670

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions microsandbox versions prior to 0.5.10
Description The software serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repeated --env arguments within sdk/rust/lib/runtime/spawn.rs and crates/cli/lib/sandbox cmd.rs. Local users or co-resident processes can read these secrets via the host process table, such as /proc process command lines on Linux and process listings on Linux and macOS, for the duration of the sandbox. This can lead to the disclosure of host-side API keys, tokens, and environment secrets on shared hosts, CI runners, and developer systems without requiring code execution inside the sandbox or access to the spawning user's session.
Recommendations Update to version 0.5.10.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61670
GHSA-M8F5-RH7H-VGG3

Affected Products

Microsandbox