Browse all 6 CVE security advisories affecting daytonaio. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54320 | Daytona: Cross-tenant organization takeover via invitation acceptance with an unverified email — daytona CWE-287 | 8.4 | High | 2026-06-23 |
| CVE-2026-54321 | Daytona: Public sandbox previews remain accessible for up to one hour after being made private — daytona CWE-613 | 7.0 | High | 2026-06-23 |
| CVE-2026-54319 | Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape — daytona CWE-22 | 4.2 | Medium | 2026-06-23 |
| CVE-2026-54322 | Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles — daytona CWE-639 | 7.7 | High | 2026-06-23 |
| CVE-2026-54324 | Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join — daytona CWE-639 | 6.5 | Medium | 2026-06-23 |
| CVE-2026-54323 | Daytona: Git credential leak via git clone with TLS verification disabled — daytona CWE-295 | 5.9 | Medium | 2026-06-23 |
This page lists every published CVE security advisory associated with daytonaio. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.