<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:53:18.848613+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326574</id>
    <title>EUVD-2026-326574</title>
    <updated>2026-10-03T01:53:18.948092+00:00</updated>
    <content>EUVD-2026-326574</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46695</id>
    <title>fkie_cve-2026-46695</title>
    <updated>2026-10-03T01:53:18.948131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform arbitrary write operations on directories that should be read-only. This issue has been patched in version 0.9.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g6ww-w5j2-r7x3</id>
    <title>GHSA-g6ww-w5j2-r7x3 — BoxLite: Permission Bypass Allows Modification of Read-Only Files</title>
    <updated>2026-10-03T01:53:18.948166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: boxlite, npm: @boxlite-ai/boxlite, Go: github.com/boxlite-ai/boxlite/sdks/go, crates.io: boxlite, crates.io: boxlite-cli</p>
<p>#### Summary</p>
<p>Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code.</p>
<p>One of the core security features claimed by Boxlite is the ability to mount host directories in read-only mode (read_only=True) into the VM via the virtiofs protocol (a host-guest shared filesystem protocol designed specifically for virtual machines), so that untrusted code can only read but not modify host data. Since the underlying function of the lightweight VM library libkrun used by Boxlite does not support mounting in read-only mode, Boxlite chooses to implement read-only by adding the MS_RDONLY flag when mounting the directory after the VM starts.</p>
<p>However, because Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform arbitrary write operations on directories that should be read-only.</p>
<p>In typical usage scenarios of Boxlite, an attacker can leverage this vulnerability to gain code execution capability on the host. For example, in AI Agent scenarios, user code, virtual environments, credentials, configuration files, and other content are often mounted in read-only mode into the container. Malicious code inside the sandbox can modify this information, such as planting malicious code, to gain code execution capability on the host, which may…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g6ww-w5j2-r7x3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-299</id>
    <title>PYSEC-2026-299 — BoxLite: Permission Bypass Allows Modification of Read-Only Files</title>
    <updated>2026-10-03T01:53:18.948283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: boxlite</p>
<p>#### Summary</p>
<p>Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code.</p>
<p>One of the core security features claimed by Boxlite is the ability to mount host directories in read-only mode (read_only=True) into the VM via the virtiofs protocol (a host-guest shared filesystem protocol designed specifically for virtual machines), so that untrusted code can only read but not modify host data. Since the underlying function of the lightweight VM library libkrun used by Boxlite does not support mounting in read-only mode, Boxlite chooses to implement read-only by adding the MS_RDONLY flag when mounting the directory after the VM starts.</p>
<p>However, because Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform arbitrary write operations on directories that should be read-only.</p>
<p>In typical usage scenarios of Boxlite, an attacker can leverage this vulnerability to gain code execution capability on the host. For example, in AI Agent scenarios, user code, virtual environments, credentials, configuration files, and other content are often mounted in read-only mode into the container. Malicious code inside the sandbox can modify this information, such as planting malicious code, to gain code execution capability on the host, which may…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-299"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2026-0147</id>
    <title>RUSTSEC-2026-0147 — Read-only volume remount bypass via guest CAP_SYS_ADMIN</title>
    <updated>2026-10-03T01:53:18.948385+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: boxlite</p>
<p>Affected versions of `boxlite` mount host directories shared via virtiofs
as guest-side read-only by setting `MS_RDONLY` from the guest. Because the
default guest capability set included `CAP_SYS_ADMIN`, untrusted code
running inside a sandbox could execute `mount -o remount,rw &lt;path&gt;` to
re-flag the share as read-write and then write through to the host
filesystem — fully escaping the read-only contract `boxlite` advertised
to callers.</p>
<p>The fix in v0.9.0 enforces read-only at the hypervisor level via
`krun_add_virtiofs3` (so the guest's `MS_RDONLY` is no longer the
authoritative gate) and drops `CAP_SYS_ADMIN` from the default guest
capability set (matching Docker's defaults).</p>
<p>This is a sandbox-escape bug: `boxlite` is a sandboxing runtime, so the
read-only invariant is part of its security contract. CVSS rated 10.0 by
the upstream advisory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2026-0147"/>
  </entry>
</feed>
