CVE-2026-108592: mini-swe-agent 1.10.0 through 2.4.6 Environment Exposure via BubblewrapEnvironment

Published Oct 10, 2026
·
Updated

mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.

Affected Software

1 affected component
pypi/mini-swe-agent>=1.10.0<=2.4.6

Event History

Oct 10, 2026
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments using mini-swe-agent versions 1.10.0 through 2.4.6 with BubblewrapEnvironment are exposed when the agent processes attacker-controlled task content. Hosts that provide API keys or other secrets through environment variables are at particular risk.

2

What does an attacker need to exploit it?

An attacker needs to inject instructions into task content processed by the agent. Exploitation also relies on the sandboxed command inheriting sensitive host environment variables and being able to exfiltrate them over the shared network.

3

Is user interaction required?

Yes. The supplied vector identifies user interaction as required, and the described attack depends on prompt injection in content that the agent processes.

4

How can I determine whether secrets may already be exposed?

Check whether affected mini-swe-agent versions were run with BubblewrapEnvironment and whether API keys or other sensitive values were present in the host environment. Review processed task content and network activity for indications that sandboxed commands transmitted environment-derived data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203