Docker Sandboxes CVE-2026-77179 and CVE-2026-79994: when the agent VM can still reach the host
Docker Sandboxes CVE-2026-77179 and CVE-2026-79994: when the agent VM can still reach the host Docker Sandboxes is the feature that runs an AI coding agent inside a purpose-built virtual machine, so that whatever the agent does stays out of the developer's environment. In September 2026 Docker published two advisories showing that a process inside that virtual machine could reach the host anyway. The first issue is CVE-2026-77179. It affects the virtio-fs host server used to share files with the sandbox, in versions from 0.28.0 up to but not including 0.42.0. Docker rated it critical and the C
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in