CVE-2026-54324
MEDIUMDaytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Title source: cnaDescription
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authorization flaw in Daytona's notification WebSocket gateway allowed any authenticated user to subscribe to another organization's realtime notification channel and passively receive that organization's events. This vulnerability is fixed in 0.185.0.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/daytonaio/daytona/security/advisories/GHSA-qwxf-2m7m-2m3x
Scores
CVSS v3
6.5
EPSS
0.0027
EPSS Percentile
19.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
CWE-863
Status
published
Products (2)
daytonaio/daytona
0 - 0.185.0Go
daytonaio/daytona
< 0.185.0
Published
Jun 23, 2026
Tracked Since
Jun 24, 2026