Symlink Vulnerability in Boxlite Sandbox Service
CVE-2026-46703
9.6CRITICAL
What is CVE-2026-46703?
Boxlite, a sandboxing service that enables users to run untrusted code within isolated virtual machines, has a security flaw present in versions prior to 0.9.0. This vulnerability arises from insufficient handling of symbolic links in OCI images. Attackers can craft malicious OCI images that point to absolute file paths, granting them the ability to manipulate files on the host once the image is loaded by a user. This can ultimately lead to arbitrary code execution on the host machine. Boxlite has addressed this issue in version 0.9.0, ensuring safer operations for users.
Affected Version(s)
boxlite < 0.9.0
