{"id":"CVE-2026-79994","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-79994","summary":"The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest…","details":"The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side capabilities provided by the targeted socket.","published":"2026-09-15T21:16:42.913","modified":"2026-09-15T21:16:42.913","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/docker/sailor/pull/2021","label":"docker/sailor#2021"},"references":[{"type":"WEB","url":"https://docs.docker.com/ai/sandboxes/"},{"type":"WEB","url":"https://docs.docker.com/ai/sandboxes/security/isolation/"},{"type":"WEB","url":"https://github.com/docker/sailor/pull/2021"},{"type":"WEB","url":"https://github.com/docker/sandboxes/pull/5342"},{"type":"WEB","url":"https://github.com/docker/sbx-releases/releases/tag/v0.41.0"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T21:16:42.913"}}