MediumVulnerabilityLLM-specific
CVE-2026-108592: mini-swe-agent information exposure in BubblewrapEnvironment sandbox
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108592
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
mini-swe-agent versions 1.10.0 through 2.4.6 contain an information exposure flaw in BubblewrapEnvironment. The bwrap invocation omits --clearenv, so sandboxed commands inherit the host environment. An attacker using prompt injection in processed task content can make the agent read API keys from that environment and exfiltrate them over the shared network.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumCVE-2026-108600: open-multi-agent link following flaw in file_write tool sandboxSimilar attack · NVD/CVE Database
- MediumCVE-2026-108599: phi symlink escape in permission gate allows writes outside workspaceSimilar attack · NVD/CVE Database
- MediumCVE-2026-108583: zotero-mcp server-side request forgery via zotero_add_by_urlSimilar attack · NVD/CVE Database
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database