ACVEAgent configuration vulnerability registry

ACVE-2026-0436

Docker Sandboxes below 0.42.0, running code from a sandboxed coding project, let guest code reach macOS host files or host-side Unix sockets outside the authorized workspace.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

ClaimStatusSourceChecked
Identifier CVE-2026-77179Confirmedcveawg.mitre.org2026-09-24
Identifier CVE-2026-79994Confirmedcveawg.mitre.org2026-09-24
Fixed in 0.42.0Confirmedcveawg.mitre.org2026-09-24
Fixed in 4.88.0Detectedcveawg.mitre.org
Severity CRITICAL; matches CNAConfirmedcveawg.mitre.org2026-09-24

In the wild

demonstrated

Description

What

Docker's security announcement describes two Docker Sandboxes flaws fixed in 0.42.0. One allowed guest code on macOS to access host files outside the shared workspace; the other allowed a guest to reach host-side Unix sockets outside that workspace.

Detection

Recorded from Docker's security announcement and the contemporaneous report. Not recreated in a lab.

Fix

Upgrade Docker Sandboxes to 0.42.0 or later; Docker recommends clone mode and avoiding read-write host mounts if an update is not possible.

Fix

Upgrade Docker Sandboxes to 0.42.0 or later and Docker Desktop to 4.88.0 or later.

  • Upgrade harness:docker-sandboxes to 0.42.0. First release that fixes both Docker Sandboxes CVEs. Owner: operator
  • Upgrade harness:docker-desktop to 4.88.0. Fix stated by the reporter for Docker Desktop. Owner: operator

References

REPORT

Report a problemJSON