CVE-2026-108592: mini-swe-agent 1.10.0 through 2.4.6 Environment Exposure via BubblewrapEnvironment
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using mini-swe-agent versions 1.10.0 through 2.4.6 with BubblewrapEnvironment are exposed when the agent processes attacker-controlled task content. Hosts that provide API keys or other secrets through environment variables are at particular risk.
What does an attacker need to exploit it?
An attacker needs to inject instructions into task content processed by the agent. Exploitation also relies on the sandboxed command inheriting sensitive host environment variables and being able to exfiltrate them over the shared network.
Is user interaction required?
Yes. The supplied vector identifies user interaction as required, and the described attack depends on prompt injection in content that the agent processes.
How can I determine whether secrets may already be exposed?
Check whether affected mini-swe-agent versions were run with BubblewrapEnvironment and whether API keys or other sensitive values were present in the host environment. Review processed task content and network activity for indications that sandboxed commands transmitted environment-derived data.