GHSA-9gqj-5w7c-vx47

Suggest an improvement
Source
https://github.com/advisories/GHSA-9gqj-5w7c-vx47
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-9gqj-5w7c-vx47/GHSA-9gqj-5w7c-vx47.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9gqj-5w7c-vx47
Aliases
Published
2025-12-04T16:55:06Z
Modified
2025-12-05T12:42:56.950316Z
Severity
  • 1.8 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing
Details

Due to a bug in sandboxing logic, sandbox-runtime did not properly enforce a network sandbox if the sandbox policy did not configure any allowed domains. This could allow sandboxed code to make network requests outside of the sandbox. A patch for this was released in v0.0.16.

Thank you to https://github.com/bendrucker for reporting this issue!

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-693"
    ],
    "nvd_published_at": "2025-12-04T21:16:09Z",
    "github_reviewed_at": "2025-12-04T16:55:06Z",
    "severity": "LOW"
}
References

Affected packages

npm / @anthropic-ai/sandbox-runtime

Package

Name
@anthropic-ai/sandbox-runtime
View open source insights on deps.dev
Purl
pkg:npm/%40anthropic-ai/sandbox-runtime

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-9gqj-5w7c-vx47/GHSA-9gqj-5w7c-vx47.json"