daytonaio has 4 CVEs on record. The busiest recent month was June 2026 with 4. The median CVSS is 6.8 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-54322High· 7.7Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles42CVE-2026-54321High· 7.0Daytona: Public sandbox previews remain accessible for up to one hour after being made private39CVE-2026-54324Medium· 6.5Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join36CVE-2026-54319Medium· 4.2Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape23
daytonaio vulnerabilities
CVEs affecting daytonaio, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-54319Medium· 4.2Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.24%via GHSA
CVE-2026-54324Medium· 6.5Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.46%via GHSA
CVE-2026-54321High· 7.0Daytona: Public sandbox previews remain accessible for up to one hour after being made private
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
▾ Twilightdaytonaio · github.com/daytonaio/daytonaEPSS 0.40%via GHSA
CVE-2026-54322High· 7.7Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
▾ Twilightdaytonaio · github.com/daytonaio/daytonaEPSS 0.30%via GHSA