๐Ÿ” CVE Alert

CVE-2026-77179

UNKNOWN 0.0

Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

CWE CWE-59
Vendor docker
Product docker sandboxes
Ecosystems
Industries
Technology
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker sandboxes

Be the first to know when new unknown vulnerabilities affecting docker docker sandboxes are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Sandboxes
0.28.0 < 0.42.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.docker.com: https://docs.docker.com/ai/sandboxes/ docs.docker.com: https://docs.docker.com/ai/sandboxes/security/isolation/ github.com: https://github.com/docker/sbx-releases/releases/tag/v0.41.0

Credits

Oren Yomtov of accomplish.ai