MEDIUM

CVE-2026-54324

2026-06-23 CVSS v3.1
CVSS
6.5

Description

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authorization flaw in Daytona's notification WebSocket gateway allowed any authenticated user to subscribe to another organization's realtime notification channel and passively receive that organization's events. This vulnerability is fixed in 0.185.0.

Summary dbcve.org

A cross-tenant authorization bypass vulnerability in Daytona's WebSocket notification gateway allowed any authenticated user to subscribe to another organization's realtime notification channel. This enabled passive interception of events from other tenants, exposing potentially sensitive organizational data through the WebSocket subscription mechanism.

Mitigation

Upgrade Daytona to version 0.185.0 or later to remediate the cross-tenant authorization flaw in the WebSocket notification gateway.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)
CWE-863 Incorrect Authorization

EPSS Score

0.46%
Probability of exploitation in next 30 days
38.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE