Impact
mini-swe-agent 1.10.0 through 2.4.6 contains a weakness that allows the sandboxed environment to inherit host environment variables because the bwrap invocation omits the --clearenv flag. This vulnerability is formally classified as CWE‑526, an information disclosure flaw. An attacker who can inject prompts into tasks processed by the agent can read sensitive API keys stored in the host environment and exfiltrate them across the shared network, compromising confidentiality of secrets but not directly enabling code execution or arbitrary system changes.
Affected Systems
The affected product is mini‑swe‑agent from SWE‑agent, versions 1.10.0 through 2.4.6. No other vendors or product variants appear to be affected according to the CNA vendor/product list.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, and the EPSS score is not available, meaning current data does not provide an exploitation probability. Since the vulnerability is listed as not present in KEV, there is no documented exploitation in the wild as of this analysis. The likely attack vector is through crafted task content that triggers prompt injection in the agent; if an attacker can influence the content processed by the agent, they can read environment variables and exfiltrate secrets. The attack requires the attacker to control or view the task content handled by the agent, so it is a local or indirect remote vector depending on the deployment context.
OpenCVE Enrichment