AI description
CVE-2026-79994 describes a vulnerability found in the guest-to-host Unix-domain socket relay within Docker Sandboxes. The flaw arises because the system first validates that a socket path is located within an authorized workspace, but then subsequently reconnects using the same pathname. This time-of-check to time-of-use (TOCTOU) vulnerability allows a malicious guest to exploit the brief interval between validation and reconnection. By replacing an intermediate directory with a symlink during this window, the guest can trick the host into connecting to an arbitrary AF_UNIX socket outside of the intended shared workspace. This could potentially lead to the exposure of data or host-side capabilities provided by the targeted socket.
- Description
- The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side capabilities provided by the targeted socket.
- Source
- security@docker.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- security@docker.com
- CWE-367
- Hype score
- Not currently trending
Docker issued warnings about symlink escapes (CVE-2026-77179) and TOCTOU race conditions in Unix sockets (CVE-2026-79994). Are your containers handling resource creation atomically? #Docker #CVE #TOCTOU #DevOps
@Nishanth_KJ
23 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 #devopsish https://t.co/umLKsEGtxy
@ChrisShort
21 Sept 2026
331 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Docker Sandboxes (microVM layer for Claude Code / Codex / Cursor / Copilot / etc.) closed two macOS host escapes: • CVE-2026-77179 (CVSS 9.4): virtio-fs symlink race → read/modify arbitrary host files as the VMM user • CVE-2026-79994 (8.7): Unix-socket relay TOCTOU →
@hazemomier
20 Sept 2026
167 Impressions
0 Retweets
5 Likes
0 Bookmarks
4 Replies
0 Quotes
现在各家都在搞 sandbox,睡前顺手发两个高危漏洞, 大家也方便自查一下。 CVE-2026-77179 和 CVE-2026-79994,评分 9.4 和 8.7 , 正好在打 Docker Sandbox。 当然,最近还有很多其他的,都没幸免 🤣 过些天看情况再
@aiandcloud
19 Sept 2026
1189 Impressions
1 Retweet
7 Likes
2 Bookmarks
2 Replies
0 Quotes
Docker patched CVE-2026-77179 (CVSS 9.4), a Docker Sandboxes macOS escape via virtio-fs symlinks, and CVE-2026-79994. Update to 0.42.0+ to prevent guest code from reading/writing host files. Details: https://t.co/lEHjZhrtFI https://t.co/QC14eBVf0C #2workly
@2Workly
18 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Your AI agent's sandbox just became the escape hatch. Docker Sandboxes CVE-2026-77179 (Critical 9.4) + CVE-2026-79994 (High 8.7) let code inside the agent VM reach the macOS host. Fixed in 0.42.0. https://t.co/6O1TFji5Da https://t.co/O8S7do0q6x
@aratech_social
18 Sept 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Docker Sandboxes has a serious security problem. Two vulnerabilities, CVE-2026-77179 and CVE-2026-79994, can break the isolation protecting AI coding agents and expose host-level files and Unix sockets. CVE-2026-77179 carries a CVSS 9.4 Critical rating. CVE-2026-79994 is
@thecybersecguru
18 Sept 2026
184 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
1 Quote
Sandbox nie jest magiczną granicą bezpieczeństwa. CVE-2026-77179 i CVE-2026-79994 pokazują, że kod agenta AI może przebić izolację Docker Sandboxes. Aktualizuj do 0.42.0+ i traktuj sandbox jak każdą inną warstwę security. #Docker #AI #Security https://t.co/y4HpY6
@quietcodelife
18 Sept 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Docker patched a critical macOS sandbox escape (CVE-2026-77179) and a high-severity socket relay flaw (CVE-2026-79994) in Sandboxes 0.42.0 on September 7. https://t.co/f6yLYKBPTl
@brockerorg
17 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Docker Sandboxes’ta ciddi açıklar bulundu! CVE-2026-77179 ve CVE-2026-79994, kötü amaçlı bir container’ın izole ortamdan çıkıp host sistemdeki hassas kaynaklara erişmesine yol açabiliyor. Açıklar 0.42.0 sürümünde kapatıldı. #Docker #CyberSecurity http
@KubbeSiber
17 Sept 2026
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilidades críticas en Docker permiten escapar de microVMs aisladas Docker ha solucionado dos vulnerabilidades graves (CVE-2026-77179 y CVE-2026-79994) en Docker Sandboxes https://t.co/47aKd02VnG
@elhackernet
17 Sept 2026
3747 Impressions
7 Retweets
34 Likes
8 Bookmarks
0 Replies
0 Quotes
Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today. #Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity https://t.co/jai8yOriPY
@Daily_CyberSec
17 Sept 2026
416 Impressions
0 Retweets
2 Likes
3 Bookmarks
0 Replies
0 Quotes
Docker security announcements | Docker Docs Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 https://t.co/ajvcO0VeJm
@autumn_good_35
16 Sept 2026
407 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes