Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
Go/github.com/daytonaio/daytona — 4 CVEs · VulnScope
pkg:Go/
github.com/daytonaio/daytona
4 total CVEs
HIGH
2
MEDIUM
2
✅ Check your installed version
Check
All known vulnerabilities
HIGH
7.7
CVE-2026-54322
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
from 0, < 0.185.0
HIGH
7.0
CVE-2026-54321
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
>= 0.101.0, < 0.184.0
MEDIUM
6.5
CVE-2026-54324
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
from 0, < 0.185.0
MEDIUM
4.2
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
from 0, < 0.186.0
CVE-2026-54319