blob: deb99b11b6e7340f23b6c3fcf4190233ef0bd001 [file]
id: GO-2026-5367
modules:
- module: github.com/daytonaio/daytona
versions:
- fixed: 0.186.0
vulnerable_at: 0.185.0
summary: |-
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into
the sandbox — cross-tenant data access and host escape in github.com/daytonaio/daytona
cves:
- CVE-2026-54319
ghsas:
- GHSA-fjv8-j4p5-cr9m
references:
- advisory: https://github.com/daytonaio/daytona/security/advisories/GHSA-fjv8-j4p5-cr9m
source:
id: GHSA-fjv8-j4p5-cr9m
created: 2026-06-25T02:54:58.37945723-04:00
review_status: UNREVIEWED