CVE-2026-54321 PUBLISHED

Daytona: Public sandbox previews remain accessible for up to one hour after being made private

Assigner: GitHub_M
Reserved: 12.06.2026 Published: 23.06.2026 Updated: 23.06.2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a cached visibility state that was not invalidated when the sandbox's visibility changed. This vulnerability is fixed in 0.184.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
CVSS Score: 7

Product Status

Vendor daytonaio
Product daytona
Versions
  • Version >= 0.101.0, < 0.184.0 is affected

References

Problem Types

  • CWE-613: Insufficient Session Expiration CWE
  • CWE-863: Incorrect Authorization CWE