github.comproduct
https://github.com/vxcontrol/pentagi CVE-2026-14784
MEDIUM
vxcontrol PentAGI Docker API client.go sandbox
Record summary
CVE-2026-14784 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PentAGIBrowse vxcontrol / PentAGI | CVE List | 2.0 | affected |
| 2.1.0 | affected |
References
8github.comissue tracking
https://github.com/vxcontrol/pentagi/issues/337 github.comissue trackingpatch
https://github.com/vxcontrol/pentagi/pull/355 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-14784 CVE-2026-14784 | CVE Analysis and ReportThird-party advisory
https://vuldb.com/cve/CVE-2026-14784 Submit #849298 | vxcontrol pentagi <=v2.1.0 Container EscapeThird-party advisory
https://vuldb.com/submit/849298 VDB-376374 | vxcontrol PentAGI Docker API client.go sandboxvdb entry
https://vuldb.com/vuln/376374 VDB-376374 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/vuln/376374/cti