{"id":"CVE-2026-54319","title":"Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape","summary":"Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape","severity":"medium","cvss":4.2,"cwe":["CWE-20","CWE-22","CWE-250","CWE-269"],"vendor":"daytonaio","product":"github.com/daytonaio/daytona","affected":["github.com/daytonaio/daytona <= 0.185.0"],"patched":["github.com/daytonaio/daytona 0.186.0"],"published":"2026-06-18","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-fjv8-j4p5-cr9m","references":[{"url":"https://github.com/daytonaio/daytona/security/advisories/GHSA-fjv8-j4p5-cr9m"},{"url":"https://github.com/advisories/GHSA-fjv8-j4p5-cr9m"}],"tags":["ghsa","go"],"ingestedAt":"2026-06-19T03:39:00.796Z","epss":0.00243,"epssPercentile":0.15764,"ecosystem":"go","slug":"CVE-2026-54319","body":"## Overview\n\n## Summary\nA sandbox volume reference (`volumeId`, which may also be a volume name) was forwarded to the\nrunner and used to build the host bind-mount source path without confinement. A reference\ncontaining path-traversal sequences could in principle resolve the mount source outside the\nintended per-volume base directory.\n\n## Impact\nHad the traversal been reachable, an authenticated user could have caused the runner to\nbind-mount an unintended host path into their sandbox, with a worst-case impact of read and\nwrite access to other tenants' volume data (per-volume FUSE mounts are world-readable and\nwritable).\n\nImportant: this path was not exploitable in any released version. A volume reference is\nvalidated against the database before it reaches the runner, and the volume id column is a\nUUID type, so a reference containing traversal sequences is rejected at validation time and\nthe request fails before any mount is constructed. We could not reproduce cross-tenant access\nor an out-of-base host mount on a released build; the observable effect of the documented\npayload was a server-side validation error. Severity is assessed as Medium on that basis.\n\n## Patches\nFixed in v0.186.0. Volume references are now resolved to the canonical volume UUID\nserver-side before reaching the runner, so a name can never flow downstream as a path\ncomponent, and the runner confines the mount source to the volume base directory and rejects\nany non-UUID reference.\n\n## Workarounds\nUpgrade to v0.186.0 or later. No configuration workaround is required for released versions,\nwhich were not exploitable.\n\n## Credit\nReported by @vnth4nhnt from CyStack.\n\n## Affected packages\n\n- `github.com/daytonaio/daytona <= 0.185.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/daytonaio/daytona 0.186.0`","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}