Description
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
Published: 2026-10-10
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

mini-swe-agent 1.10.0 through 2.4.6 contains a weakness that allows the sandboxed environment to inherit host environment variables because the bwrap invocation omits the --clearenv flag. This vulnerability is formally classified as CWE‑526, an information disclosure flaw. An attacker who can inject prompts into tasks processed by the agent can read sensitive API keys stored in the host environment and exfiltrate them across the shared network, compromising confidentiality of secrets but not directly enabling code execution or arbitrary system changes.

Affected Systems

The affected product is mini‑swe‑agent from SWE‑agent, versions 1.10.0 through 2.4.6. No other vendors or product variants appear to be affected according to the CNA vendor/product list.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity, and the EPSS score is not available, meaning current data does not provide an exploitation probability. Since the vulnerability is listed as not present in KEV, there is no documented exploitation in the wild as of this analysis. The likely attack vector is through crafted task content that triggers prompt injection in the agent; if an attacker can influence the content processed by the agent, they can read environment variables and exfiltrate secrets. The attack requires the attacker to control or view the task content handled by the agent, so it is a local or indirect remote vector depending on the deployment context.

Generated by OpenCVE AI on October 10, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update mini‑swe‑agent to a version in which BubblewrapEnvironment invokes bwrap with the --clearenv flag or otherwise prevents environment inheritance; if no patched release is available, apply the patch from the mini‑swe‑agent repository that adds --clearenv or rewrites the bubblewrap.py file accordingly.
  • Restrict the agent’s execution environment to a non‑privileged user and remove or mask environment variables that hold secret values before launching the sandboxed process, ensuring the sandbox has no access to host secrets.
  • Sanitize or validate all task content that will be sent to the agent, rejecting or escaping any payload that attempts to reference environment variables or perform prompt injection to prevent unintended code execution.

Generated by OpenCVE AI on October 10, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
Title mini-swe-agent 1.10.0 through 2.4.6 Environment Exposure via BubblewrapEnvironment
Weaknesses CWE-526
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T18:16:56.528Z

Reserved: 2026-10-10T18:08:11.425Z

Link: CVE-2026-108592

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T19:16:57.463

Modified: 2026-10-10T19:16:57.463

Link: CVE-2026-108592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T19:30:17Z

Weaknesses
  • CWE-526

    Cleartext Storage of Sensitive Information in an Environment Variable