Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54323— Daytona: Git credential leak via git clone with TLS verification disabled

Quick assessment

Affected
daytonaio daytona
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Daytona Daytona是美国Daytona团队的一个安全且弹性的基础架构运行时环境,专为 AI 生成的代码执行和代理工作流而设计。 Daytona 0.185.0之前版本存在加密问题漏洞,该漏洞源于daemon的git clone实现禁用了TLS证书验证,可能导致攻击者拦截克隆流量,呈现任意TLS证书并捕获Git凭据,以及向沙箱提供篡改的仓库内容。

CVSS 5.9 · Medium EPSS 0.18% · P7

Affected Version Matrix 1

VendorProduct Version RangeStatus
daytonaio daytona < 0.185.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54323

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Daytona: Git credential leak via git clone with TLS verification disabled
Source: CVE Program / CVE List V5
Vulnerability Description
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization header to the remote over a connection whose certificate was never validated, on both the go-git and native git CLI code paths. An attacker able to intercept clone traffic could present any TLS certificate, capture the Git credentials supplied for the clone, and serve tampered repository content into the sandbox. This vulnerability is fixed in 0.185.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Daytona 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Daytona Daytona是美国Daytona团队的一个安全且弹性的基础架构运行时环境,专为 AI 生成的代码执行和代理工作流而设计。 Daytona 0.185.0之前版本存在加密问题漏洞,该漏洞源于daemon的git clone实现禁用了TLS证书验证,可能导致攻击者拦截克隆流量,呈现任意TLS证书并捕获Git凭据,以及向沙箱提供篡改的仓库内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
daytonaio daytona < 0.185.0 -

II. Public POCs for CVE-2026-54323

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54323

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-54323 (1)

Same Patch Batch · daytonaio · 2026-06-23 · 6 CVEs total

CVE-2026-54320 8.4 HIGH Daytona: Cross-tenant organization takeover via invitation acceptance with an unverified e
CVE-2026-54322 7.7 HIGH Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or
CVE-2026-54321 7.0 HIGH Daytona: Public sandbox previews remain accessible for up to one hour after being made pri
CVE-2026-54324 6.5 MEDIUM Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizat
CVE-2026-54319 4.2 MEDIUM Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox

IV. Related Vulnerabilities

V. Comments for CVE-2026-54323

No comments yet


Leave a comment