CVE-2026-108592
mini-swe-agent 1.10.0 through 2.4.6 Environment Exposure via BubblewrapEnvironment
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
| CWE | CWE-526 |
| Vendor | swe-agent |
| Product | mini-swe-agent |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for swe-agent mini-swe-agent
Be the first to know when new medium vulnerabilities affecting swe-agent mini-swe-agent are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
SWE-agent / mini-swe-agent
1.10.0 โค 2.4.6
References
hackmd.io: https://hackmd.io/@haind/minisweagent-bubblewrap-host-environment-leak github.com: https://github.com/SWE-agent/mini-swe-agent/blob/v2.4.6/src/minisweagent/environments/extra/bubblewrap.py#L38-L103 github.com: https://github.com/SWE-agent/mini-swe-agent vulncheck.com: https://www.vulncheck.com/advisories/mini-swe-agent-1.10.0-through-2.4.6-environment-exposure-via-bubblewrapenvironment
Credits
HaiND from the Post and Telecommunication Institute of Technology