github.com/daytonaio/daytona vulnerabilities
CVEs whose affected-version data names the github.com/daytonaio/daytona package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-54319Medium· 4.2Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.24%via GHSA
CVE-2026-54324Medium· 6.5Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.46%via GHSA
CVE-2026-54321High· 7.0Daytona: Public sandbox previews remain accessible for up to one hour after being made private
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
▾ Twilightdaytonaio · github.com/daytonaio/daytonaEPSS 0.40%via GHSA
CVE-2026-54322High· 7.7Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
▾ Twilightdaytonaio · github.com/daytonaio/daytonaEPSS 0.30%via GHSA