{"id":"CVE-2025-66479","aliases":["GHSA-9gqj-5w7c-vx47"],"url":"https://o3.security/vulnerability/CVE-2025-66479","summary":"Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing","details":"Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. Prior to 0.0.16, due to a bug in sandboxing logic, sandbox-runtime did not properly enforce a network sandbox if the sandbox policy did not configure any allowed domains. This could allow sandboxed code to make network requests outside of the sandbox. A patch for this was released in v0.0.16.","published":"2025-12-04T20:57:20.631Z","modified":"2026-09-08T03:45:38.041087948Z","cvss":null,"epss":{"score":0.0016,"percentile":0.05319,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@anthropic-ai/sandbox-runtime","fixedVersion":"0.0.16"}],"fix":{"url":"https://github.com/anthropic-experimental/sandbox-runtime/commit/bea2930cc1db9c73a1b15acf6dc19c5261aec1f3","label":"anthropic-experimental/sandbox-runtime@bea2930"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66479.json"},{"type":"ADVISORY","url":"https://github.com/anthropic-experimental/sandbox-runtime/security/advisories/GHSA-9gqj-5w7c-vx47"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66479"},{"type":"FIX","url":"https://github.com/anthropic-experimental/sandbox-runtime/commit/bea2930cc1db9c73a1b15acf6dc19c5261aec1f3"},{"type":"PACKAGE","url":"https://github.com/anthropic-experimental/sandbox-runtime"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-08T03:45:38.041087948Z"}}