CVE-2026-108592
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Oct 10, 2026
Vendor
unknown
Description
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
References
- https://github.com/SWE-agent/mini-swe-agent
- https://github.com/SWE-agent/mini-swe-agent/blob/v2.4.6/src/minisweagent/environments/extra/bubblewrap.py#L38-L103
- https://hackmd.io/@haind/minisweagent-bubblewrap-host-environment-leak
- https://www.vulncheck.com/advisories/mini-swe-agent-1.10.0-through-2.4.6-environment-exposure-via-bubblewrapenvironment