Link following in Docker Sandboxes - CVE-2026-77179

 

Link following in Docker Sandboxes - CVE-2026-77179

Published: September 16, 2026


Vulnerability identifier: #VU150198
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77179
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to read or modify arbitrary host files.

The vulnerability exists due to improper handling of symbolic links in the virtio-fs host server on macOS when reopening an unlinked file from a stored path. A local user can replace a parent directory with a symbolic link to escape the shared workspace and read or modify arbitrary host files.

This may potentially lead to code execution on the host.


Affected software

Docker Sandboxes

How to mitigate CVE-2026-77179

Install security update from vendor's website.

Docker Sandboxes - update to 0.42.0

External References

Related Security Bulletins