{"id":"GHSA-fjv8-j4p5-cr9m","summary":"Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape","details":"## Summary\nA sandbox volume reference (`volumeId`, which may also be a volume name) was forwarded to the\nrunner and used to build the host bind-mount source path without confinement. A reference\ncontaining path-traversal sequences could in principle resolve the mount source outside the\nintended per-volume base directory.\n\n## Impact\nHad the traversal been reachable, an authenticated user could have caused the runner to\nbind-mount an unintended host path into their sandbox, with a worst-case impact of read and\nwrite access to other tenants' volume data (per-volume FUSE mounts are world-readable and\nwritable).\n\nImportant: this path was not exploitable in any released version. A volume reference is\nvalidated against the database before it reaches the runner, and the volume id column is a\nUUID type, so a reference containing traversal sequences is rejected at validation time and\nthe request fails before any mount is constructed. We could not reproduce cross-tenant access\nor an out-of-base host mount on a released build; the observable effect of the documented\npayload was a server-side validation error. Severity is assessed as Medium on that basis.\n\n## Patches\nFixed in v0.186.0. Volume references are now resolved to the canonical volume UUID\nserver-side before reaching the runner, so a name can never flow downstream as a path\ncomponent, and the runner confines the mount source to the volume base directory and rejects\nany non-UUID reference.\n\n## Workarounds\nUpgrade to v0.186.0 or later. No configuration workaround is required for released versions,\nwhich were not exploitable.\n\n## Credit\nReported by @vnth4nhnt from CyStack.","aliases":["CVE-2026-54319","GO-2026-5367"],"modified":"2026-07-20T21:30:27.048383500Z","published":"2026-06-18T17:19:51Z","database_specific":{"nvd_published_at":"2026-06-23T19:17:07Z","cwe_ids":["CWE-20","CWE-22","CWE-250","CWE-269"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-18T17:19:51Z"},"references":[{"type":"WEB","url":"https://github.com/daytonaio/daytona/security/advisories/GHSA-fjv8-j4p5-cr9m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54319"},{"type":"PACKAGE","url":"https://github.com/daytonaio/daytona"}],"affected":[{"package":{"name":"github.com/daytonaio/daytona","ecosystem":"Go","purl":"pkg:golang/github.com/daytonaio/daytona"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.186.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.185.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fjv8-j4p5-cr9m/GHSA-fjv8-j4p5-cr9m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}