deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Docker Sandboxes flaws let AI agent VMs read and modify host files

Two Docker Sandboxes vulnerabilities let code inside an AI agent's virtual machine read and modify arbitrary files on the host. Both are fixed in version 0.42.0, released 7 September 2026.

Docker Sandboxes flaws let AI agent VMs read and modify host files

Two flaws broke the sandbox boundary

Docker Sandboxes is Docker's mechanism for running an AI coding agent in its own virtual machine, keeping whatever the agent does away from the developer's actual system. In September 2026, according to a detailed write-up on dev.to, Docker published advisories for two vulnerabilities showing that a process inside that VM could reach the host anyway. Both were fixed in version 0.42.0, released on 7 September 2026; the advisories and CVE records followed on 15 September, alongside a 0.43.0 release.

The virtio-fs flaw, rated critical

The first issue, CVE-2026-77179, carries a critical rating and a CVSS score of 9.4. It affects the virtio-fs host server used to share files with the sandbox, in releases from 0.28.0 up to (but not including) 0.42.0, and applies to macOS, where the shared filesystem is implemented through virtio-fs.

The impact is direct: code running inside the per-agent VM could read and alter arbitrary files on the host, beyond the shared project directory, using the privileges of the host account. The shared folder is the boundary the feature advertises, and this defect meant it was not the real limit. The finding is credited to Oren Yomtov of accomplish.ai.

A second defect in the socket relay

The second issue, CVE-2026-79994, carries a severity rating of 8.7 and affects versions from 0.37.0 up to (but not including) 0.42.0. It concerns a Unix socket relay that carries communication between the guest and the host. Per the dev.to summary, Docker's advisory does not name an affected platform for this one and describes the mechanism rather than a full reproduction. Jurre van Bergen of ThreatNotify is credited with the report.

The pairing is notable on its own: the shared filesystem and the socket relay are the two channels a sandbox uses to communicate with its host, and both carried a defect within overlapping version ranges.

A corrected CVE record

For anyone tracking vulnerability inventory, the record for CVE-2026-79994 initially listed 0.41.0 as the fixed version and was corrected to 0.42.0 about an hour later. Tools that cached the early entry may still report the wrong fix version.

What to do

Update to 0.42.0 or later, with 0.43.0 as the current build. Where a host cannot be updated immediately, Docker's documented interim measure is to run sandboxes in --clone mode, which works only with Git repositories and mounts the source read-only at /run/sandbox/source. The dev.to post flags a caveat worth stating plainly: .env files and untracked files inside the repository remain readable, because they are part of the checked-out tree.

Docker reported no in-the-wild exploitation, and neither issue appeared in CISA's Known Exploited Vulnerabilities catalogue as of 16 September 2026, according to the dev.to write-up.

After patching, it is worth auditing what the sandbox could have touched during the exposure window, particularly files outside the project directory and any credentials stored in the developer's home directory. Because the first flaw grants modification as well as read access, an integrity check on shell startup files and Git configuration is a sensible follow-up.

Why it matters

Sandboxed virtual machines are quickly becoming the default way to run AI coding agents safely, and these CVEs are a reminder that the isolation is only as strong as the host-side services implementing it. Docker's own documentation frames the sandbox as a hypervisor boundary rather than a privilege boundary inside the VM: processes running in the guest are not separated from one another, so everything depends on the barrier the hypervisor enforces. A bug in the host component that implements file sharing weakens precisely that layer.

For security teams, the useful question shifts from whether the agent is trusted to what the host-side service is allowed to touch on the guest's behalf, and how that is verified. These two flaws, in the very components that mediate guest-to-host communication, are a concrete illustration of why that question matters.

  • #docker
  • #security
  • #cve
  • #ai-agents
  • #sandboxing

Related posts