CVE-2026-54321: Daytonaio Daytona

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a cached visibility state that was not invalidated when the sandbox's visibility changed. This vulnerability is fixed in 0.184.0.

Affected products

  • Daytonaio Daytona: from 0.101.0, before 0.184.0 (fixed in 0.184.0)

Published 2026-06-23. Last modified 2026-06-25.