MicroVM Runtime Vulnerability in Microsandbox by Super Rad Company
CVE-2026-61670
6.5MEDIUM
What is CVE-2026-61670?
Microsandbox, a local-first microVM runtime, is susceptible to an improper access control vulnerability that exposes NetworkConfig secrets transmitted through command-line arguments. Versions prior to 0.5.10 allow other local users or co-resident processes to access sensitive values via the host process table. This flaw can reveal critical host-side API keys, tokens, and environment secrets in shared environments, including CI runners and developer systems, without requiring code execution within the sandbox or direct access to the spawning user's session. A patch has been released in version 0.5.10 to address this issue.
Affected Version(s)
microsandbox < 0.5.10
