Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-54322 | 7.7 HIGH | Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or |
| CVE-2026-54321 | 7.0 HIGH | Daytona: Public sandbox previews remain accessible for up to one hour after being made pri |
| CVE-2026-54324 | 6.5 MEDIUM | Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizat |
| CVE-2026-54323 | 5.9 MEDIUM | Daytona: Git credential leak via git clone with TLS verification disabled |
| CVE-2026-54319 | 4.2 MEDIUM | Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox |
No comments yet