CVE-2026-46703
Boxlite is a sandbox service that lets users run untrusted OCI containers in lightweight virtual machines. Versions before 0.9.0 fail to check for symlinks that point to absolute paths inside container images, allowing a malicious image to write files anywhere on the host.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Boxlite sandbox service running any version earlier than 0.9.0.
Real-world impact
An attacker can craft a malicious OCI image, trick a user into loading it, and then write arbitrary files to any location on the host system. This can lead to full remote code execution on the host.
Why this severity
The CVSS score of 9.6 reflects that the vulnerability is network‑exposed, requires no user interaction beyond loading a container image, and gives an attacker complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Boxlite to version 0.9.0 or later.
NVD-referenced vendor advisory
Timeline
- Jun 10, 2026 · Jun 10, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 23, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.