Symlink Vulnerability in Boxlite Sandbox Service
CVE-2026-46703

9.6CRITICAL

Key Information:

Vendor

Boxlite-ai

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-46703?

Boxlite, a sandboxing service that enables users to run untrusted code within isolated virtual machines, has a security flaw present in versions prior to 0.9.0. This vulnerability arises from insufficient handling of symbolic links in OCI images. Attackers can craft malicious OCI images that point to absolute file paths, granting them the ability to manipulate files on the host once the image is loaded by a user. This can ultimately lead to arbitrary code execution on the host machine. Boxlite has addressed this issue in version 0.9.0, ensuring safer operations for users.

Affected Version(s)

boxlite < 0.9.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.