Description
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
Published: 2026-09-15
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary host file write and potential code execution
Action: Apply Workaround
AI Analysis

Impact

Docker Sandboxes’ virtio‑fs host server on macOS incorrectly follows symlinks when re‑opening an unlinked file from the stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution. This flaw corresponds to CWE‑59 and carries a CVSS score of 9.4.

Affected Systems

The vulnerability affects Docker Sandboxes running on macOS. The CNA data lists the product but does not specify a version range, meaning any deployment that uses the default virtio‑fs implementation is potentially exposed.

Risk and Exploitability

The risk is high, reflected by the CVSS score of 9.4. The EPSS score is < 1%, indicating a low but non-zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, yet the attack requires only local execution inside a guest image. An attacker can craft a symlink attack, escape isolation, and write to to code execution on the host system. The exploit requires no external network access and relies solely on the ability to run or influence a Docker Sandbox guest.

Generated by OpenCVE AI on September 17, 2026 at 15:45 UTC.

Remediation

Vendor Workaround

Use --clone mode and avoid additional read-write host mounts: https://docs.docker.com/ai/sandboxes/usage/#clone-mode


OpenCVE Recommended Actions

  • Use the recommended clone mode and avoid additional read‑write host mounts as described in the Docker documentation.
  • If a patched version of Docker Sandboxes is available, upgrade to the latest release as soon as possible.
  • Restrict the shared workspace by disabling virtio‑fs mounts or applying strict read‑only policies to reduce the attack surface until a fix is applied.

Generated by OpenCVE AI on September 17, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
References

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
References

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
Title Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback
First Time appeared Docker
Docker docker Sandboxes
Weaknesses CWE-59
CPEs cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*
Vendors & Products Docker
Docker docker Sandboxes
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Docker Docker Sandboxes
cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-09-15T21:43:07.049Z

Reserved: 2026-08-20T15:32:02.935Z

Link: CVE-2026-77179

cve-icon Vulnrichment

Updated: 2026-09-15T15:01:02.531Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T14:17:11.273

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-77179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T15:45:17Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')