Daytona AI code-execution runtime discloses six flaws including cross-tenant access
Six CVEs were published for Daytona, an infrastructure runtime for AI-generated code execution and agent workflows, covering cross-tenant authorization flaws in its notification WebSocket gateway and organization role endpoints, unverified-email invitation acceptance, stale sandbox preview visibility caching, a volume path-traversal bind-mount issue, and git clone with TLS certificate verification disabled that could leak Git credentials. All issues are fixed in releases 0.184.0 through 0.186.
Disclosed 23 June 2026 · Record updated 13 September 2026
Impact
Attackers could receive another organization's realtime notifications, modify or delete another organization's roles, join an organization via an unverified email invitation (up to Owner role), reach sandbox previews after they were made private, capture Git credentials and serve tampered repository content via unverified TLS, and potentially resolve volume mount sources outside the intended directory.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54323
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54324
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54319
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54320
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54321
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54322
