{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0436",
  "aliases": [
    "CVE-2026-77179",
    "CVE-2026-79994"
  ],
  "published": "2026-09-07T00:00:00Z",
  "firstReported": {
    "date": "2026-09-07",
    "url": "https://docs.docker.com/security/security-announcements/",
    "publisher": "Docker"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Docker Sandboxes below 0.42.0, running code from a sandboxed coding project, let guest code reach macOS host files or host-side Unix sockets outside the authorized workspace.",
  "details": "## What\n\nDocker's security announcement describes two Docker Sandboxes flaws fixed in 0.42.0. One allowed guest code on macOS to access host files outside the shared workspace; the other allowed a guest to reach host-side Unix sockets outside that workspace.\n\n## Detection\n\nRecorded from Docker's security announcement and the contemporaneous report. Not recreated in a lab.\n\n## Fix\n\nUpgrade Docker Sandboxes to 0.42.0 or later; Docker recommends clone mode and avoiding read-write host mounts if an update is not possible.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "docker-sandboxes"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0.28.0"
            },
            {
              "fixed": "0.42.0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "docker-desktop"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.88.0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://docs.docker.com/security/security-announcements/"
    },
    {
      "type": "REPORT",
      "url": "https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html"
    },
    {
      "type": "REPORT",
      "url": "https://accomplish.ai/blog/escaping-dockers-hypervisor/"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "sandbox-escape",
        "path-traversal"
      ],
      "cwe": [
        "CWE-61",
        "CWE-367"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI05"
        ],
        "atlas": [
          "AML.T0105"
        ]
      },
      "cveBoundary": "cve-aliased",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://docs.docker.com/security/security-announcements/",
            "type": "vendor"
          },
          {
            "url": "https://accomplish.ai/blog/escaping-dockers-hypervisor/",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Upgrade Docker Sandboxes to 0.42.0 or later and Docker Desktop to 4.88.0 or later.",
        "actions": [
          {
            "type": "upgrade",
            "target": "harness:docker-sandboxes",
            "to": "0.42.0",
            "why": "First release that fixes both Docker Sandboxes CVEs.",
            "owner": "operator"
          },
          {
            "type": "upgrade",
            "target": "harness:docker-desktop",
            "to": "4.88.0",
            "why": "Fix stated by the reporter for Docker Desktop.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Docker Sandboxes 0.28.0 to before 0.42.0, and Docker Desktop with Docker VMM before 4.88.0",
          "any": false,
          "status": "detected",
          "source": "https://docs.docker.com/security/security-announcements/"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any coding-agent task running code in a Docker Sandbox",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Docker Sandboxes guest filesystem sharing and guest-to-host Unix socket relay",
          "status": "confirmed",
          "source": "https://docs.docker.com/security/security-announcements/"
        },
        "approval": {
          "value": "Code running in the guest can reach host resources through the sandbox boundary",
          "mode": "sandbox-escape",
          "status": "confirmed",
          "source": "https://docs.docker.com/security/security-announcements/"
        },
        "inputControl": "repo-author",
        "agentAction": "The sandboxed guest reaches host files or host-side socket capabilities outside the authorized workspace.",
        "harm": "arbitrary-command",
        "divergence": "none",
        "reach": {
          "value": "Host files and host-side Unix socket capabilities",
          "kinds": [
            "home-directory",
            "project-files",
            "network"
          ],
          "status": "confirmed",
          "source": "https://docs.docker.com/security/security-announcements/"
        }
      },
      "claims": [
        {
          "kind": "identifier",
          "statement": "Identifier CVE-2026-77179",
          "value": "CVE-2026-77179",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-77179",
          "result": "match",
          "observed": "CVE.org: PUBLISHED",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:23Z"
        },
        {
          "kind": "identifier",
          "statement": "Identifier CVE-2026-79994",
          "value": "CVE-2026-79994",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-79994",
          "result": "match",
          "observed": "CVE.org: PUBLISHED",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:23Z"
        },
        {
          "kind": "fixed-version",
          "statement": "Fixed in 0.42.0",
          "value": "0.42.0",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-77179",
          "result": "match",
          "observed": "CVE.org structured: lessThan 0.42.0; affected-version 0.28.0; affected-version 0.37.0",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:23Z"
        },
        {
          "kind": "fixed-version",
          "statement": "Fixed in 4.88.0",
          "value": "4.88.0",
          "status": "detected",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-77179",
          "method": "machine"
        },
        {
          "kind": "severity",
          "statement": "Severity CRITICAL; matches CNA",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-77179",
          "observed": "CNA: CRITICAL 9.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H); CNA: HIGH 8.7 (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N); OSV: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H); OSV: (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N)",
          "result": "match",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:23Z"
        }
      ],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
