CVE-2026-77179

Published Sep 15, 2026

Last updated 11 days ago

CVSS critical 9.4
Docker
Container Security

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-77179 describes a vulnerability found in Docker Sandboxes on macOS, specifically within the virtio-fs host server component. This flaw, categorized as improper link resolution before file access (CWE-59), arises because the virtio-fs host server incorrectly follows symbolic links when attempting to reopen an unlinked file from a previously stored path. Exploitation of this vulnerability involves a malicious guest within a Docker Sandbox replacing a parent directory with a symlink. This action allows the guest to escape the confines of the shared workspace, leading to unauthorized access where arbitrary host files can be read or modified with the privileges of the Virtual Machine Monitor (VMM) user. This could potentially enable host code execution. The vulnerability affects Docker Sandboxes versions 0.28.0 up to, but not including, 0.42.0, and was addressed in version 0.42.0.

Description
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
Source
security@docker.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

security@docker.com
CWE-59

Social media

Hype score
Not currently trending
  1. #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 19-26, 2026) 1⃣. Simple MacOS Docker Escape https://t.co/MP4dxWY56T // CVE-2026-77179 2⃣. Brevo ClickFix Compromise https://t.co/wnujTK1ipc // malicious "ClickFix" script served via Brev

    @ksg93rd

    26 Sept 2026

    165 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  2. Docker issued warnings about symlink escapes (CVE-2026-77179) and TOCTOU race conditions in Unix sockets (CVE-2026-79994). Are your containers handling resource creation atomically? #Docker #CVE #TOCTOU #DevOps

    @Nishanth_KJ

    23 Sept 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Docker assigned CVE-2026-77179 to its own Sandboxes product. On macOS, the virtio-fs host server followed a symlink when it reopened an unlinked file from a stored path. A guest that could replace a parent directory walked out of the shared workspace and read or wrote host http

    @BigVikDada

    22 Sept 2026

    89 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    4 Replies

    0 Quotes

  4. Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 #devopsish https://t.co/umLKsEGtxy

    @ChrisShort

    21 Sept 2026

    331 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. แจ้งเตือน! ช่องโหว่ใน Docker Sandboxes บน macOS เสี่ยงถูกอ่านหรือแก้ไขไฟล์บนเครื่องหลัก ผู้ใช้งานควรอัปเดตทันที

    @ThaiCERTByNCSA

    21 Sept 2026

    78 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Docker Sandboxes (microVM layer for Claude Code / Codex / Cursor / Copilot / etc.) closed two macOS host escapes: • CVE-2026-77179 (CVSS 9.4): virtio-fs symlink race → read/modify arbitrary host files as the VMM user • CVE-2026-79994 (8.7): Unix-socket relay TOCTOU →

    @hazemomier

    20 Sept 2026

    167 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    4 Replies

    0 Quotes

  7. 现在各家都在搞 sandbox,睡前顺手发两个高危漏洞, 大家也方便自查一下。 CVE-2026-77179 和 CVE-2026-79994,评分 9.4 和 8.7 , 正好在打 Docker Sandbox。 ​ ​当然,最近还有很多其他的,都没幸免 🤣 过些天看情况再

    @aiandcloud

    19 Sept 2026

    1189 Impressions

    1 Retweet

    7 Likes

    2 Bookmarks

    2 Replies

    0 Quotes

  8. Docker patched CVE-2026-77179 (CVSS 9.4), a Docker Sandboxes macOS escape via virtio-fs symlinks, and CVE-2026-79994. Update to 0.42.0+ to prevent guest code from reading/writing host files. Details: https://t.co/lEHjZhrtFI https://t.co/QC14eBVf0C #2workly

    @2Workly

    18 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CRITICAL: Docker Sandbox Escape Can Reach the macOS Host A critical vulnerability in Docker Sandboxes could allow malicious code running inside a sandbox to escape its intended workspace and read or modify host files. 🔴 CVE-2026-77179 CVSS: 9.4 Critical The flaw lives i

    @SpectraAudit

    18 Sept 2026

    44 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  10. DOCKER SANDBOXES ESCAPE FLAW ON macOS CVE-2026-77179 let malicious code inside a Docker Sandboxes VM break out and touch host files. CVSS 9.4. Fixed in 0.42.0. Read more: https://t.co/7DcVe5d3aR #Docker #DockerSandboxes #CVE #SandboxEscape #macOS #InfoSec #ThreatIntel https://

    @redsecuretech

    18 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Your AI agent's sandbox just became the escape hatch. Docker Sandboxes CVE-2026-77179 (Critical 9.4) + CVE-2026-79994 (High 8.7) let code inside the agent VM reach the macOS host. Fixed in 0.42.0. https://t.co/6O1TFji5Da https://t.co/O8S7do0q6x

    @aratech_social

    18 Sept 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 Docker Sandboxes has a serious security problem. Two vulnerabilities, CVE-2026-77179 and CVE-2026-79994, can break the isolation protecting AI coding agents and expose host-level files and Unix sockets. CVE-2026-77179 carries a CVSS 9.4 Critical rating. CVE-2026-79994 is

    @thecybersecguru

    18 Sept 2026

    184 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    1 Quote

  13. Sandbox nie jest magiczną granicą bezpieczeństwa. CVE-2026-77179 i CVE-2026-79994 pokazują, że kod agenta AI może przebić izolację Docker Sandboxes. Aktualizuj do 0.42.0+ i traktuj sandbox jak każdą inną warstwę security. #Docker #AI #Security https://t.co/y4HpY6

    @quietcodelife

    18 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Docker sandbox escape on macOS lets a malicious container read/modify host files via CVE-2026-77179; patch now, restrict host dirs, and review workload isolation. What does this prove about your runtime boundaries and supply chain containment? A reminder: vendor promises ≠ real

    @arnavsharma

    18 Sept 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Docker patched a critical macOS sandbox escape (CVE-2026-77179) and a high-severity socket relay flaw (CVE-2026-79994) in Sandboxes 0.42.0 on September 7. https://t.co/f6yLYKBPTl

    @brockerorg

    17 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Docker Sandboxes'ta kritik sandbox escape açığı Docker Sandboxes'ta keşfedilen CVE-2026-77179, kötü niyetli kodun sandbox izolasyonunu aşarak macOS host üzerindeki dosyaları okumasına/değiştirmesine, potansiyel olarak host üzerinde kod çalıştırmasına yol

    @ridvanyagli

    17 Sept 2026

    119 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Major warning for developers: two serious flaws in Docker Sandboxes allow guest code to escape the project directory and access or modify macOS host files. These affect versions up to 0.41.9, with a Critical issue in virtio-fs (CVE-2026-77179) and a High-severity socket-relay bug

    @dailytechonx

    17 Sept 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 Docker Sandboxes’ta ciddi açıklar bulundu! CVE-2026-77179 ve CVE-2026-79994, kötü amaçlı bir container’ın izole ortamdan çıkıp host sistemdeki hassas kaynaklara erişmesine yol açabiliyor. Açıklar 0.42.0 sürümünde kapatıldı. #Docker #CyberSecurity http

    @KubbeSiber

    17 Sept 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Vulnerabilidades críticas en Docker permiten escapar de microVMs aisladas Docker ha solucionado dos vulnerabilidades graves (CVE-2026-77179 y CVE-2026-79994) en Docker Sandboxes https://t.co/47aKd02VnG

    @elhackernet

    17 Sept 2026

    3747 Impressions

    7 Retweets

    34 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  20. Docker disclosed two Docker Sandboxes vulnerabilities that can allow malicious guest environments to escape workspace isolation and access host resources. CVE-2026-77179, affecting macOS versions before 0.42.0, enables symlink-race redirection of filesystem operations,

    @LandscapeThreat

    17 Sept 2026

    58 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  21. Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today. #Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity https://t.co/jai8yOriPY

    @Daily_CyberSec

    17 Sept 2026

    416 Impressions

    0 Retweets

    2 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  22. Docker security announcements | Docker Docs Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 https://t.co/ajvcO0VeJm

    @autumn_good_35

    16 Sept 2026

    407 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes