Docker patches two critical Sandboxes flaws
Docker disclosed CVE-2026-77179 (CVSS 9.4) and CVE-2026-79994 (CVSS 8.7) in its Sandboxes feature, letting code inside the agent VM read and modify host files. Both are fixed in version 0.42.0, released 7 September 2026.
- CVE-2026-77179: critical 9.4, affects versions 0.28.0–0.41.x on macOS
- CVE-2026-79994: rated 8.7, affects versions 0.37.0–0.41.x
- Fix shipped in 0.42.0; 0.43.0 is the current build
- Interim workaround is --clone mode, but .env and untracked files stay readable
Read next
Security