CVE-2026-108592: Swe-Agent Mini-Swe-Agent
Medium severity, CVSS 5.3.
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
Affected products
- Swe-Agent Mini-Swe-Agent: from 1.10.0, up to and including 2.4.6
Published 2026-10-10. Last modified 2026-10-10.