Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-77179

Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback
Back to all
CVE

CVE-2026-77179

Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.4
-
4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://docs.docker.com/ai/sandboxes/, https://docs.docker.com/ai/sandboxes/security/isolation/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77179.json, https://github.com/docker/sbx-releases/releases/tag/v0.42.0, https://nvd.nist.gov/vuln/detail/CVE-2026-77179

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00199%
EPSS Percentile
0.08867%
Introduced Version
4a0fbcf0599c8d81714500242eed24fcdce24c55
Fix Available
bdfd32bd69bb084959b5f4779310bff21d95bb62

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading