漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Vulnerability Description
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume reference (volumeId, which may also be a volume name) was forwarded to the runner and used to build the host bind-mount source path without confinement. A reference containing path-traversal sequences could in principle resolve the mount source outside the intended per-volume base directory. This vulnerability is fixed in 0.186.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Daytona 路径遍历漏洞
Vulnerability Description
Daytona Daytona是美国Daytona团队的一个安全且弹性的基础架构运行时环境,专为 AI 生成的代码执行和代理工作流而设计。 Daytona 0.186之前版本存在安全漏洞,该漏洞源于sandbox volume reference(volumeId,也可能是volume name)被转发给runner并用于构建主机bind-mount源路径时未进行限制,包含路径遍历序列的引用可能将挂载源解析到预期的每卷基目录之外。
CVSS Information
N/A
Vulnerability Type
N/A