{"data":{"id":"74271e94-bf43-44bb-9f53-c9b854c6405e","title":"CVE-2026-108592: mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because…","summary":"mini-swe-agent versions 1.10.0 through 2.4.6 contain an information exposure flaw in BubblewrapEnvironment. The bwrap invocation omits --clearenv, so sandboxed commands inherit the host environment. An attacker using prompt injection in processed task content can make the agent read API keys from that environment and exfiltrate them over the shared network.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108592","publishedAt":"2026-10-10T19:16:57.463Z","cveId":"CVE-2026-108592","cweIds":["CWE-526"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection","data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["mini-swe-agent"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"mini-swe-agent information exposure in BubblewrapEnvironment sandbox","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T00:10:11.192Z","kevDateAdded":null,"advisoryAliases":["GHSA-p449-r4wm-3hpm"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T00:10:15.692Z","patchAvailable":null,"disclosureDate":"2026-10-10T19:16:57.463Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}}