Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-108592: mini-swe-agent information exposure in BubblewrapEnvironment sandbox

Identifier
CVE-2026-108592
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

mini-swe-agent versions 1.10.0 through 2.4.6 contain an information exposure flaw in BubblewrapEnvironment. The bwrap invocation omits --clearenv, so sandboxed commands inherit the host environment. An attacker using prompt injection in processed task content can make the agent read API keys from that environment and exfiltrate them over the shared network.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.