CVE-2026-54321 Details
Description
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a cached visibility state that was not invalidated when the sandbox's visibility changed. This vulnerability is fixed in 0.184.0.
A vulnerability in Daytona, a runtime for AI-generated code execution, allows unauthorized access to private sandbox previews for a limited time after they are made private. This issue affects versions 0.101.0 through 0.183.0. The vulnerability arises because the proxy server did not immediately update the cached visibility state when a sandbox was switched from public to private. As a result, the preview could still be accessed without authentication on regular preview ports, except for terminal, toolbox, and recording-dashboard ports, which always require authentication.
Users can upgrade to Daytona version 0.184.0 or later to address this vulnerability. For versions prior to 0.184.0, there is no configuration workaround available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/daytonaio/daytona/security/advisories/GHSA-ww63-pv5x-vfc8 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Daytona | >= 0.101.0, <= 0.183.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion