Two critical vulnerabilities in boxlite allow attackers to break isolation guarantees and write to the host filesystem. The first flaw, tracked as CVE-2026-46703 and RUSTSEC-2026-0148, affects OCI image layer extraction: a crafted image can abuse symlink handling in tarball extraction to escape the intended rootfs directory and perform arbitrary host file writes. GitHub’s advisory says the bug can be triggered by malicious OCI images that place symlinks pointing outside the extraction root, causing later files to be written to locations such as /etc or /tmp; if Boxlite runs as root, the issue could lead to remote code execution on the host.
A second critical issue, CVE-2026-46695 and RUSTSEC-2026-0147, lets code inside a boxlite sandbox remount a shared virtiofs host directory from read-only to read-write because the guest retained CAP_SYS_ADMIN while relying on MS_RDONLY. That bypass undermined Boxlite’s advertised read-only isolation and enabled writes back to the host from within the guest. Both flaws were fixed in boxlite 0.9.0: the extraction bug was addressed by routing filesystem operations through a SafeRoot handle using openat2 with RESOLVE_IN_ROOT on Linux, while the remount bypass was mitigated by enforcing read-only access at the hypervisor layer and removing CAP_SYS_ADMIN from the default guest capability set.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The symlink escape vulnerability in boxlite's OCI extraction process was formally issued as CVE-2026-46703. The CVE assignment followed the initial report and public disclosure of the arbitrary host write issue.
Boxlite released version 0.9.0 to address both critical flaws. The update enforced read-only virtiofs access at the hypervisor level and removed CAP_SYS_ADMIN from the default guest capability set, while also routing destructive filesystem operations through a SafeRoot handle using openat2 with RESOLVE_IN_ROOT on Linux and a lexical fallback on other platforms.
Security advisories published for boxlite disclosed two critical vulnerabilities: CVE-2026-46695, which let sandboxed code remount a read-only virtiofs share as writable due to retained CAP_SYS_ADMIN, and CVE-2026-46703, which enabled arbitrary host file writes via OCI layer symlink escape during image extraction. Both issues were described as enabling host filesystem compromise from untrusted workloads or images.
A critical path traversal flaw in boxlite's OCI layer extraction logic was reported, allowing crafted symlink and file entries to escape the intended rootfs and write arbitrary files to the host filesystem. The issue was later tracked as CVE-2026-46703 and credited to the XlabAI Team of Tencent Xuanwu Lab and the Atuin Automated Vulnerability Discovery Engine.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
rustsec.org
Open sourcerustsec.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.