@thecybersecguru@infosec.exchange
2026-09-18 06:49 UTC
🚨 Docker Sandboxes escape vulnerabilities
Two flaws could allow malicious code running inside a Docker Sandbox to break out of the microVM isolation and reach the underlying host:
• CVE-2026-77179 | CVSS 9.4 Critical | virtio-fs symlink escape
• CVE-2026-79994 | CVSS 8.7 High | Unix socket relay TOCTOU
The risk is especially interesting for AI coding agents that can autonomously execute code and interact with untrusted repositories.
Docker addressed the flaws in Sandbox 0.42.0.
Technical breakdown:
https://thecybersecguru.com/news/docker-sandboxes-cve-2026-77179-cve-2026-79994/
#InfoSec #CyberSecurity #Docker #AISecurity #CVE #DevSecOps
Replies (0)
No replies.