---
id: CVE-2026-108592
title: >-
  mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure
  vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so
  sandboxed commands inherit the host environment
summary: >-
  mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure
  vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so
  sandboxed commands inherit the host environment. Attackers using prompt
  injection in processed…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-526
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T19:16:57.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108592'
references:
  - url: 'https://github.com/SWE-agent/mini-swe-agent'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/SWE-agent/mini-swe-agent/blob/v2.4.6/src/minisweagent/environments/extra/bubblewrap.py#L38-L103
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@haind/minisweagent-bubblewrap-host-environment-leak'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mini-swe-agent-1.10.0-through-2.4.6-environment-exposure-via-bubblewrapenvironment
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T19:30:07.152Z'
---

## Overview

mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
