CVE-2026-77179
CVE-2026-77179
9.4
CriticalPublished:
Last updated:
Source:security@docker.com
Awaiting Analysis
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Local
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
References
security@docker.com
https://docs.docker.com/ai/sandboxes/security@docker.com
https://docs.docker.com/ai/sandboxes/security/isolation/security@docker.com
https://github.com/docker/sbx-releases/releases/tag/v0.42.0