Vulnerability  ·  2026-10-11

mini-swe-agent Bubblewrap sandbox omits --clearenv → prompt-injected agent exfiltrates host API keys (CVSS 5.3)

VulnerabilityHigh impactGlobalCVE-2026-108592
Verified via NVD REST API (published 2026-10-10, VulnCheck). The sandbox is intended to isolate agent commands but the environment variables are inherited, combining an agent sandbox isolation flaw with prompt injection.
This is precisely the agent-sandbox-escape class defenders must patch: a coding agent processing untrusted task text can be steered into reading developer/CI API keys that should never be visible inside the sandbox.
bwrap omits --clearenv so sandboxed commands inherit the full host environment; an attacker plants prompt-injected instructions in the task content the agent processes, and the agent exfiltrates API keys from the environment over the shared network (CWE-526).
mini-swe-agent 1.10.0 through 2.4.6 (BubblewrapEnvironment)
Upgrade past 2.4.6 and ensure bwrap is invoked with an explicit clean environment; sanitize task content provenance. See VulnCheck advisory and hackmd write-up.
NVD CVE-2026-108592NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →