CVE-2026-108592

Source
https://cve.org/CVERecord?id=CVE-2026-108592
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108592.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-108592
Published
2026-10-10T18:16:56Z
Modified
2026-10-11T02:46:55Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
mini-swe-agent 1.10.0 through 2.4.6 Environment Exposure via BubblewrapEnvironment
Details

mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-526"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108592.json"
}
References

Affected packages

Git / github.com/swe-agent/mini-swe-agent

Affected ranges

Type
GIT
Repo
https://github.com/swe-agent/mini-swe-agent
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.10.0"
        },
        {
            "last_affected": "2.4.6"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.10.0
v1.11.0
v1.11.1
v1.12.0
v1.13.0
v1.13.1
v1.13.2
v1.13.3
v1.13.4
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.14.4
v1.15.0
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v2.*
v2.0.0
v2.0.0a1
v2.0.0a2
v2.0.0a3
v2.1.0
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.3.0
v2.3.1
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108592.json"