oM noM Security Feeds cve
vulnerability context

CVE-2026-46703

CVSS 9.6 CRITICALEPSS 38%CWE-22OTX 9 pulses

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to absolute paths. An attacker can craft a malicious OCI image and distribute it on image hosting platforms such as DockerHub, tricking users into using it. Once a user loads the malicious image, the attac...

Published 2026-06-10 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
9.6 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
38% percentile (score 0.0048)
CWE
CWE-22
OTX pulses
9 total, 0 recent

source mentions 2

source consensus

  • Bluesky
  • GitHub Advisories
Want the 3-bullet summary of CVE-2026-46703, plus webhook alerts when KEV is updated? Pro is $10/mo.