CVE-2026-53657High· 8.2▾ TwilightLima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.1%
0.1% → 0.2%
On an instance of Lima running with qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled.
This could result in running an arbitrary command with the root privileges in the VM (not on the host), as lima-guestagent.sock provides the tunneling service for an arbitrary address, including a Unix socket address for privileged daemons like D-Bus.
This vulnerability is not exploitable on vz driver, as the guest agent uses vsocks instead of Unix sockets.
Patched in Lima v2.1.3 (8a45892378d22f40505c31a38f786a07701b6d50)
[!NOTE] The default user account in the VM can still run an arbitrary command as the root via the guest agent socket. This is not a vulnerability, as the user can already run an arbitrary command with
sudoby design.
vz driver instead of qemu (limactl create --vm-type=vz. Default since v1.0.)limactl create --plain)github.com/lima-vm/lima/v2 <= 2.1.2Upgrade to a patched release:
github.com/lima-vm/lima/v2 2.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2022-38474Medium· 4.3A website that had permission to access the microphone could record audio without the audio notification being shown
CVE-2024-1488High· 8.0A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration
CVE-2025-8766Medium· 6.4A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images
CVE-2026-73843Critical· 9.6OpenChoreo is a complete, open-source developer platform for Kubernetes
CVE-2026-54495Medium· 4.3The OpenFeature Operator allows users to expose feature flags to applications
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…