CVE-2026-54324
Description
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authorization flaw in Daytona's notification WebSocket gateway allowed any authenticated user to subscribe to another organization's realtime notification channel and passively receive that organization's events. This vulnerability is fixed in 0.185.0.
Summary dbcve.org
A cross-tenant authorization bypass vulnerability in Daytona's WebSocket notification gateway allowed any authenticated user to subscribe to another organization's realtime notification channel. This enabled passive interception of events from other tenants, exposing potentially sensitive organizational data through the WebSocket subscription mechanism.
Mitigation
Upgrade Daytona to version 0.185.0 or later to remediate the cross-tenant authorization flaw in the WebSocket notification gateway.