{"id":"CVE-2026-54324","title":"Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join","summary":"Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join","severity":"medium","cvss":6.5,"cwe":["CWE-639","CWE-863"],"vendor":"daytonaio","product":"github.com/daytonaio/daytona","ecosystem":"go","affected":["github.com/daytonaio/daytona <= 0.184.0"],"patched":["github.com/daytonaio/daytona 0.185.0"],"published":"2026-06-17","updated":"2026-06-17","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-qwxf-2m7m-2m3x","references":[{"url":"https://github.com/daytonaio/daytona/security/advisories/GHSA-qwxf-2m7m-2m3x"},{"url":"https://github.com/advisories/GHSA-qwxf-2m7m-2m3x"}],"tags":["ghsa","go"],"epss":0.00456,"epssPercentile":0.38929,"ingestedAt":"2026-06-29T14:31:47.227Z","slug":"CVE-2026-54324","body":"## Overview\n\n### Summary\nA cross-tenant authorization flaw in Daytona's notification WebSocket gateway allowed any authenticated user to subscribe to another organization's realtime notification channel and passively receive that organization's events.\n\n### Impact\nThe notification gateway's JWT handshake joined a client-supplied organization identifier to the corresponding notification room without verifying that the authenticated user was a member of that organization. As a result, an authenticated user could receive another organization's realtime sandbox, snapshot, volume, and runner events, including data carried in those events. This is a cross-tenant confidentiality break. It required a valid account and knowledge of the target organization id (a non-secret UUID); no elevated privileges were needed. The API-key authentication path was not affected.\n\nThe affected component is the Daytona API service (the `apps/api` NestJS application). It is distributed through Daytona's repository releases and container images for self-hosted deployments; it is not published as a Go or npm package, so the advisory will not surface through `go get` or npm dependency tooling.\n\n### Affected Versions\n>= 0.101.0, <= 0.184.0\n\n### Patched Versions\n0.185.0\n\n### Credit\n@vnth4nhnt from CyStack\n\n## Affected packages\n\n- `github.com/daytonaio/daytona <= 0.184.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/daytonaio/daytona 0.185.0`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}