CVE-2026-54319: Daytona Path-Traversal Sandbox Escape—Patch to 0.186
Daytona, a runtime platform for executing AI-generated code and agent workflows, contains a path-traversal vulnerability in versions prior to 0.186. When users specify a volume identifier to mount storage, the system failed to properly validate the path, potentially allowing an authenticated user to reference storage locations outside the intended directories. An attacker with valid credentials could craft a specially formatted volume reference to access or modify files beyond the sandbox's intended scope.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.2 MEDIUM · CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-22, CWE-250, CWE-269
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-23 / 2026-06-24
NVD description (verbatim)
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume reference (volumeId, which may also be a volume name) was forwarded to the runner and used to build the host bind-mount source path without confinement. A reference containing path-traversal sequences could in principle resolve the mount source outside the intended per-volume base directory. This vulnerability is fixed in 0.186.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-54319 is a path-traversal vulnerability in Daytona's sandbox volume handling. The vulnerability exists in how volumeId parameters (which can be either volume identifiers or names) are processed when constructing host bind-mount source paths. Prior to version 0.186, insufficient path confinement allowed sequences like '../' or similar traversal patterns to escape the designated per-volume base directory. The runner component receives the unvalidated volumeId and uses it directly in path construction, enabling directory traversal. This maps to CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), CWE-250 (Execution with Unnecessary Privileges), and CWE-269 (Improper Access Control).
Business impact
This vulnerability primarily affects organizations running Daytona for AI code execution and agentic workflows. The exposure is limited to authenticated users, reducing the attack surface for most deployments, but the ability to access files outside sandboxed volumes could compromise code integrity, expose sensitive training data, or allow modification of execution environments. For AI development teams relying on Daytona for secure, isolated code generation and testing, this creates a sandbox-escape risk that could undermine trust in the platform's isolation guarantees.
Affected systems
Daytona versions prior to 0.186 are affected. The vulnerability requires authenticated access and depends on the runner implementation accepting and processing the unvalidated volumeId. Organizations should verify their installed version and check whether volume mounting features are exposed to trusted or semi-trusted users in their deployment model.
Exploitability
Exploitation requires valid credentials (PR:L in the CVSS vector), making this suitable for insider threats or compromised user accounts. The attack complexity is rated as high, suggesting successful exploitation may depend on specific deployment configurations or knowledge of the exact volume structure. No active exploits are currently tracked in the CISA Known Exploited Vulnerabilities catalog. The barrier to exploitation is meaningful, but the simplicity of path-traversal attacks means security teams should assume patch deployment is necessary.
Remediation
Upgrade Daytona to version 0.186 or later, which includes path-confinement fixes for volume reference handling. Organizations running earlier versions should prioritize this upgrade within their maintenance windows. After patching, verify that volume mounting works as expected in test environments before full production rollout. Review access controls around volume mounting capabilities to ensure they are granted only to necessary user roles.
Patch guidance
The fix is available in Daytona version 0.186 and later. Vendors and maintainers should consult the official Daytona release notes and advisories to confirm the exact version available for your deployment model (cloud-hosted, self-hosted, or containerized). Plan upgrades during low-usage periods to minimize disruption to AI development workflows. Test the upgrade in a non-production environment to confirm compatibility with your volume mounting configurations and any integrations.
Detection guidance
Monitor for volumeId parameters containing path-traversal sequences (e.g., '..', '%2e%2e', or similar encoded variants) in requests to volume-mounting endpoints. Log and alert on volume references that resolve to paths outside expected base directories. Examine sandbox execution logs for attempts to access files in unexpected locations. If available, enable audit logging for volume operations in your Daytona deployment to capture mount-related activities.
Why prioritize this
Although the CVSS score is moderate (4.2), this vulnerability warrants timely patching because it directly undermines sandbox isolation—a critical security property for any system executing untrusted or AI-generated code. The requirement for authentication reduces immediate risk, but insider threats and compromised accounts are persistent risks in development environments. Early patching prevents a potential foothold for lateral movement or data exfiltration within trusted infrastructure.
Risk score, explained
The CVSS 3.1 score of 4.2 (MEDIUM) reflects limited impact (only confidentiality and integrity, no availability impact), requirement for authenticated access, and high attack complexity. However, the severity understates the value of the sandbox abstraction in code-execution platforms; even limited sandbox escape is operationally significant. Organizations deeply dependent on Daytona's isolation properties should consider this a higher operational priority than the numeric score alone suggests.
Frequently asked questions
Does this vulnerability allow remote code execution outside the Daytona sandbox?
The vulnerability enables an authenticated user to traverse directories and access or modify files outside the intended per-volume base directory. While this does not automatically grant code execution, it could allow an attacker to modify code or configuration files that are subsequently executed, or to read sensitive files. The extent of damage depends on what files exist in adjacent directories and the permissions of the Daytona process.
If we restrict volume mounting to trusted administrators only, can we delay patching?
Restricting volume mounting reduces risk significantly, since the attack requires authentication and knowledge of how to craft a traversal sequence. However, patching is still recommended because administrative accounts are often targets for compromise. Treat this as a temporary mitigation while you plan and execute the upgrade to 0.186.
Are there any breaking changes in version 0.186 that we should know about before upgrading?
Verify the official Daytona release notes for version 0.186 to confirm any breaking changes or configuration adjustments. The path-confinement fix should be transparent to most users, but test the upgrade in a non-production environment first to ensure compatibility with your specific volume mounting and workflow configurations.
How can we tell if this vulnerability was exploited in our Daytona instance?
Enable and review audit logs or sandbox execution logs for volumeId references containing path-traversal patterns, and check for file access attempts outside expected directories. If your logging is limited, upgrade to 0.186 and then conduct a security review of any volumes created during the vulnerable period to identify suspicious mount points.
This analysis is based on the published CVE description and CVSS vector as of June 2026. No proof-of-concept code or active exploitation details are included. Organizations should consult official Daytona advisories and documentation for complete remediation guidance and verify all patch versions against upstream vendor sources. This assessment does not replace independent security review or testing in your specific deployment environment. Source: NVD (public-domain), retrieved 2026-07-29. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-0055MEDIUMAndroid Path Traversal in PackageInstallerService Enables Local Privilege Escalation to Device Policy Controller
- CVE-2026-50565MEDIUMFission Kubernetes Service Account Token Exposure
- CVE-2018-25393MEDIUMNavigate CMS 2.8.5 Path Traversal Vulnerability (CVSS 6.5)
- CVE-2018-25421MEDIUMOpen STA Manager 2.3 Path Traversal File Download Vulnerability
- CVE-2019-25734MEDIUMContact Form by WD CSRF & Local File Inclusion Vulnerability
- CVE-2019-25740MEDIUMJoomla com_jsjobs Arbitrary File Deletion Vulnerability
- CVE-2022-50953MEDIUMWordPress admin-word-count-column Plugin Local File Read Vulnerability
- CVE-2024-47263MEDIUMSynology Hyper Backup Path Traversal – Admin Privilege Required