Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108592

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Oct 10, 2026
Vendor unknown

Description

mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.

References