Impact
Docker Sandboxes’ virtio‑fs host server on macOS incorrectly follows symlinks when re‑opening an unlinked file from the stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution. This flaw corresponds to CWE‑59 and carries a CVSS score of 9.4.
Affected Systems
The vulnerability affects Docker Sandboxes running on macOS. The CNA data lists the product but does not specify a version range, meaning any deployment that uses the default virtio‑fs implementation is potentially exposed.
Risk and Exploitability
The risk is high, reflected by the CVSS score of 9.4. The EPSS score is < 1%, indicating a low but non-zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, yet the attack requires only local execution inside a guest image. An attacker can craft a symlink attack, escape isolation, and write to to code execution on the host system. The exploit requires no external network access and relies solely on the ability to run or influence a Docker Sandbox guest.
OpenCVE Enrichment