MicroVM Runtime Vulnerability in Microsandbox by Super Rad Company
CVE-2026-61670

6.5MEDIUM

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-61670?

Microsandbox, a local-first microVM runtime, is susceptible to an improper access control vulnerability that exposes NetworkConfig secrets transmitted through command-line arguments. Versions prior to 0.5.10 allow other local users or co-resident processes to access sensitive values via the host process table. This flaw can reveal critical host-side API keys, tokens, and environment secrets in shared environments, including CI runners and developer systems, without requiring code execution within the sandbox or direct access to the spawning user's session. A patch has been released in version 0.5.10 to address this issue.

Affected Version(s)

microsandbox < 0.5.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.