Information Exposure in mini-swe-agent from SWE-agent
CVE-2026-108592

6MEDIUM

Key Information:

Vendor

Swe-agent

Vendor
CVE Published:
10 October 2026

What is CVE-2026-108592?

The mini-swe-agent versions 1.10.0 through 2.4.6 are vulnerable due to an information exposure flaw in the BubblewrapEnvironment. This vulnerability arises because the command bwrap fails to clear the environment variables with the --clearenv option, allowing sandboxed commands to unintentionally inherit sensitive information from the host environment. Attackers can exploit this flaw through prompt injection in processed task content, enabling them to read and potentially exfiltrate critical API keys over shared networks, leading to unauthorized access and further exploitation of the affected systems.

Affected Version(s)

mini-swe-agent 1.10.0 <= 2.4.6

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.