CVE-2026-77179
Published Sep 15, 2026
Last updated 11 days ago
AI description
CVE-2026-77179 describes a vulnerability found in Docker Sandboxes on macOS, specifically within the virtio-fs host server component. This flaw, categorized as improper link resolution before file access (CWE-59), arises because the virtio-fs host server incorrectly follows symbolic links when attempting to reopen an unlinked file from a previously stored path. Exploitation of this vulnerability involves a malicious guest within a Docker Sandbox replacing a parent directory with a symlink. This action allows the guest to escape the confines of the shared workspace, leading to unauthorized access where arbitrary host files can be read or modified with the privileges of the Virtual Machine Monitor (VMM) user. This could potentially enable host code execution. The vulnerability affects Docker Sandboxes versions 0.28.0 up to, but not including, 0.42.0, and was addressed in version 0.42.0.
- Description
- On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
- Source
- security@docker.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- security@docker.com
- CWE-59
- Hype score
- Not currently trending
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 19-26, 2026) 1⃣. Simple MacOS Docker Escape https://t.co/MP4dxWY56T // CVE-2026-77179 2⃣. Brevo ClickFix Compromise https://t.co/wnujTK1ipc // malicious "ClickFix" script served via Brev
@ksg93rd
26 Sept 2026
165 Impressions
0 Retweets
1 Like
0 Bookmarks
2 Replies
0 Quotes
Docker issued warnings about symlink escapes (CVE-2026-77179) and TOCTOU race conditions in Unix sockets (CVE-2026-79994). Are your containers handling resource creation atomically? #Docker #CVE #TOCTOU #DevOps
@Nishanth_KJ
23 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Docker assigned CVE-2026-77179 to its own Sandboxes product. On macOS, the virtio-fs host server followed a symlink when it reopened an unlinked file from a stored path. A guest that could replace a parent directory walked out of the shared workspace and read or wrote host http
@BigVikDada
22 Sept 2026
89 Impressions
0 Retweets
3 Likes
1 Bookmark
4 Replies
0 Quotes
Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 #devopsish https://t.co/umLKsEGtxy
@ChrisShort
21 Sept 2026
331 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
แจ้งเตือน! ช่องโหว่ใน Docker Sandboxes บน macOS เสี่ยงถูกอ่านหรือแก้ไขไฟล์บนเครื่องหลัก ผู้ใช้งานควรอัปเดตทันที
@ThaiCERTByNCSA
21 Sept 2026
78 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Docker Sandboxes (microVM layer for Claude Code / Codex / Cursor / Copilot / etc.) closed two macOS host escapes: • CVE-2026-77179 (CVSS 9.4): virtio-fs symlink race → read/modify arbitrary host files as the VMM user • CVE-2026-79994 (8.7): Unix-socket relay TOCTOU →
@hazemomier
20 Sept 2026
167 Impressions
0 Retweets
5 Likes
0 Bookmarks
4 Replies
0 Quotes
现在各家都在搞 sandbox,睡前顺手发两个高危漏洞, 大家也方便自查一下。 CVE-2026-77179 和 CVE-2026-79994,评分 9.4 和 8.7 , 正好在打 Docker Sandbox。 当然,最近还有很多其他的,都没幸免 🤣 过些天看情况再
@aiandcloud
19 Sept 2026
1189 Impressions
1 Retweet
7 Likes
2 Bookmarks
2 Replies
0 Quotes
Docker patched CVE-2026-77179 (CVSS 9.4), a Docker Sandboxes macOS escape via virtio-fs symlinks, and CVE-2026-79994. Update to 0.42.0+ to prevent guest code from reading/writing host files. Details: https://t.co/lEHjZhrtFI https://t.co/QC14eBVf0C #2workly
@2Workly
18 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: Docker Sandbox Escape Can Reach the macOS Host A critical vulnerability in Docker Sandboxes could allow malicious code running inside a sandbox to escape its intended workspace and read or modify host files. 🔴 CVE-2026-77179 CVSS: 9.4 Critical The flaw lives i
@SpectraAudit
18 Sept 2026
44 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
DOCKER SANDBOXES ESCAPE FLAW ON macOS CVE-2026-77179 let malicious code inside a Docker Sandboxes VM break out and touch host files. CVSS 9.4. Fixed in 0.42.0. Read more: https://t.co/7DcVe5d3aR #Docker #DockerSandboxes #CVE #SandboxEscape #macOS #InfoSec #ThreatIntel https://
@redsecuretech
18 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Your AI agent's sandbox just became the escape hatch. Docker Sandboxes CVE-2026-77179 (Critical 9.4) + CVE-2026-79994 (High 8.7) let code inside the agent VM reach the macOS host. Fixed in 0.42.0. https://t.co/6O1TFji5Da https://t.co/O8S7do0q6x
@aratech_social
18 Sept 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Docker Sandboxes has a serious security problem. Two vulnerabilities, CVE-2026-77179 and CVE-2026-79994, can break the isolation protecting AI coding agents and expose host-level files and Unix sockets. CVE-2026-77179 carries a CVSS 9.4 Critical rating. CVE-2026-79994 is
@thecybersecguru
18 Sept 2026
184 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
1 Quote
Sandbox nie jest magiczną granicą bezpieczeństwa. CVE-2026-77179 i CVE-2026-79994 pokazują, że kod agenta AI może przebić izolację Docker Sandboxes. Aktualizuj do 0.42.0+ i traktuj sandbox jak każdą inną warstwę security. #Docker #AI #Security https://t.co/y4HpY6
@quietcodelife
18 Sept 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Docker sandbox escape on macOS lets a malicious container read/modify host files via CVE-2026-77179; patch now, restrict host dirs, and review workload isolation. What does this prove about your runtime boundaries and supply chain containment? A reminder: vendor promises ≠ real
@arnavsharma
18 Sept 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Docker patched a critical macOS sandbox escape (CVE-2026-77179) and a high-severity socket relay flaw (CVE-2026-79994) in Sandboxes 0.42.0 on September 7. https://t.co/f6yLYKBPTl
@brockerorg
17 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Docker Sandboxes'ta kritik sandbox escape açığı Docker Sandboxes'ta keşfedilen CVE-2026-77179, kötü niyetli kodun sandbox izolasyonunu aşarak macOS host üzerindeki dosyaları okumasına/değiştirmesine, potansiyel olarak host üzerinde kod çalıştırmasına yol
@ridvanyagli
17 Sept 2026
119 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Major warning for developers: two serious flaws in Docker Sandboxes allow guest code to escape the project directory and access or modify macOS host files. These affect versions up to 0.41.9, with a Critical issue in virtio-fs (CVE-2026-77179) and a High-severity socket-relay bug
@dailytechonx
17 Sept 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Docker Sandboxes’ta ciddi açıklar bulundu! CVE-2026-77179 ve CVE-2026-79994, kötü amaçlı bir container’ın izole ortamdan çıkıp host sistemdeki hassas kaynaklara erişmesine yol açabiliyor. Açıklar 0.42.0 sürümünde kapatıldı. #Docker #CyberSecurity http
@KubbeSiber
17 Sept 2026
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilidades críticas en Docker permiten escapar de microVMs aisladas Docker ha solucionado dos vulnerabilidades graves (CVE-2026-77179 y CVE-2026-79994) en Docker Sandboxes https://t.co/47aKd02VnG
@elhackernet
17 Sept 2026
3747 Impressions
7 Retweets
34 Likes
8 Bookmarks
0 Replies
0 Quotes
Docker disclosed two Docker Sandboxes vulnerabilities that can allow malicious guest environments to escape workspace isolation and access host resources. CVE-2026-77179, affecting macOS versions before 0.42.0, enables symlink-race redirection of filesystem operations,
@LandscapeThreat
17 Sept 2026
58 Impressions
0 Retweets
3 Likes
0 Bookmarks
2 Replies
0 Quotes
Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today. #Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity https://t.co/jai8yOriPY
@Daily_CyberSec
17 Sept 2026
416 Impressions
0 Retweets
2 Likes
3 Bookmarks
0 Replies
0 Quotes
Docker security announcements | Docker Docs Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 https://t.co/ajvcO0VeJm
@autumn_good_35
16 Sept 2026
407 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes