What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). The sandbox is intended to isolate agent commands but the environment variables are inherited, combining an agent sandbox isolation flaw with prompt injection.
Why it matters
This is precisely the agent-sandbox-escape class defenders must patch: a coding agent processing untrusted task text can be steered into reading developer/CI API keys that should never be visible inside the sandbox.
Attack vector
bwrap omits --clearenv so sandboxed commands inherit the full host environment; an attacker plants prompt-injected instructions in the task content the agent processes, and the agent exfiltrates API keys from the environment over the shared network (CWE-526).
Affected systems
mini-swe-agent 1.10.0 through 2.4.6 (BubblewrapEnvironment)
Mitigation
Upgrade past 2.4.6 and ensure bwrap is invoked with an explicit clean environment; sanitize task content provenance. See VulnCheck advisory and hackmd write-up.