Sandbox Vulnerability in Boxlite Before Version 0.9.0
CVE-2026-46695

10CRITICAL

Key Information:

Vendor

Boxlite-ai

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-46695?

Boxlite, a sandbox service that enables users to create lightweight virtual machines for running OCI containers, contains a security flaw in versions prior to 0.9.0. This vulnerability arises from insufficient restrictions on kernel capabilities within the container environment. As a result, malicious code can exploit this weakness to remount directories in read-write (rw) mode, allowing unauthorized write operations on otherwise protected directories. This flaw poses significant risks as it can enable compromised code to manipulate sensitive files and data. The issue has been addressed in the latest update, version 0.9.0, which implements necessary restrictions to prevent such exploitation.

Affected Version(s)

boxlite < 0.9.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.