Security Flaw in Daytona Infrastructure Runtime by Daytona
CVE-2026-54323

5.9MEDIUM

Key Information:

Vendor

Daytonaio

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54323?

Daytona, an infrastructure runtime designed for AI-generated code execution, has a notable security flaw related to its git clone implementation prior to version 0.185.0. This flaw allows TLS certificate verification to be bypassed, enabling an attacker to intercept clone requests. As a result, Git credentials can be exposed, and malicious tampering with repository content becomes feasible. The issue was addressed in version 0.185.0, which restores the integrity of the TLS validation process and safeguards user credentials and repository authenticity.

Affected Version(s)

daytona < 0.185.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.