Sceawere

Vulnerability Detail

CVE-2026-108592UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

mini-swe-agent Environment Variable Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
SWE-agent
Product
mini-swe-agent
Attack Type
Cleartext Storage of Sensitive Information in an Environment Variable
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T19:16:57.463Z",
  "pubdate": "2026-10-10T19:16:57.463Z",
  "executiveSummary": "The mini-swe-agent, spanning versions 1.10.0 through 2.4.6, is susceptible to an information exposure vulnerability due to improper environment variable sanitization within the BubblewrapEnvironment component.\nThe vulnerability arises because the underlying bwrap (Bubblewrap) process execution omits the --clearenv flag. Consequently, the sandboxed environment inadvertently inherits the host's full environment variable set.\nThis represents a critical security risk as sensitive credentials, including API keys and authentication tokens, are exposed to any command or process executed within the sandbox.\nAn attacker can leverage prompt injection techniques within processed task content to force the agent to read and exfiltrate these sensitive variables over the network.\nSuccessful exploitation allows unauthorized third parties to gain access to the host's secrets, potentially leading to full account takeover or lateral movement within the infrastructure.\nNo specific authentication is required to trigger this vulnerability beyond the ability to submit task content that the agent processes. The impact is significant, as it bypasses the isolation guarantees typically expected from sandboxed environments.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of the BubblewrapEnvironment component within mini-swe-agent versions 1.10.0 to 2.4.6. When the agent initializes a sandbox using bwrap, it fails to specify the --clearenv argument. By default, Bubblewrap creates a new mount namespace and process environment but inherits the parent process's environment variables unless explicitly instructed otherwise.\nIn the context of an agentic workflow, the agent frequently handles untrusted input, such as task descriptions or external repository content. If an attacker injects malicious instructions into these inputs, they can command the agent to execute shell commands within the sandbox environment. Because the environment variables—which commonly include sensitive API keys, cloud provider credentials, or session tokens—are propagated to the child process, the sandboxed command has full visibility into these secrets.\nThe attack flow proceeds as follows: 1. An attacker submits a task or repository containing a malicious payload designed for prompt injection. 2. The mini-swe-agent processes this input and triggers a sandbox execution via BubblewrapEnvironment. 3. The sandboxed shell or process, having inherited the parent's environment, accesses the sensitive variables (e.g., echo $API_KEY). 4. The attacker's payload executes a network-bound command, such as curl or wget, to transmit the captured environment variables to an attacker-controlled external server.\nThis vulnerability highlights a failure in the principle of least privilege regarding sandbox configuration. While the filesystem and network are ostensibly restricted, the environment variable vector remains an open channel for data exfiltration. The exploitation is highly reliable because environment variables are globally accessible to the calling process's context and do not require elevated privileges within the sandbox to read. Furthermore, because the environment is inherited at process creation, there is no mitigation available within the sandbox itself once the process has started; the vulnerability is structural and exists at the invocation layer of the bwrap binary."
}
CVE-2026-108592: mini-swe-agent Environment Variable Exposure (MEDIUM Severity, CVSS: 5.3) | Sceawere