Impact
The vulnerability arises because microsandbox serializes NetworkConfig secret values into the --network-config command‑line argument and passes per‑sandbox secrets through repeated --env arguments. These secrets can be read by any local user or co‑resident process via the host process table, such as /proc or process listings, for the lifetime of the sandbox. The consequence is that host‑side API keys, tokens, and environment secrets may be disclosed without code execution inside the sandbox or access to the spawning user’s session. The weakness is classified as a CWE‑214, Information Exposure Through an Improperly Managed Sensitive Data.
Affected Systems
All installations of Superradcompany microsandbox earlier than version 0.5.10 are affected. The issue resides in the Rust SDK runtime (spawn.rs) and the CLI crate sandbox_cmd.rs, and the fix is released in the v0.5.10 release. Users on Linux and macOS using earlier versions should update to any post‑0.5.10 build to avoid exposing secrets.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting moderate exploitation probability. However, the vulnerability can be leveraged by any local attacker or on shared hosts and CI runners, as secrets are exposed via process arguments that any process can read. The risk level is therefore moderate to high depending on the environment, especially if multiple users or workloads share the same host where sandbox processes run.
OpenCVE Enrichment
Github GHSA