CVE Explorer
CVE-2026-47213
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can e
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"boxlite","vendor":"boxlite-ai","versions":[{"status":"affected","version":"<= 0.8.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3a495838fc974e39c7fd3a85569642c4f184766c11420a1b60b4694590ac7389 · sha256:b05a46756c593376… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3a495838fc974e39c7fd3a85569642c4f184766c11420a1b60b4694590ac7389 · sha256:b05a46756c593376… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-404","description":"CWE-404: Improper Resource Shutdown or Release","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3a495838fc974e39c7fd3a85569642c4f184766c11420a1b60b4694590ac7389 · sha256:b05a46756c593376… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/boxlite-ai/boxlite/commit/28159fc5b6b6fd5037e18a58fc4644c882e3c581","tags":["x_refsource_MISC"],"url":"https://github.com/boxlite-ai/boxlite/commit/28159fc5b6b6fd5037e18a58fc4644c882e3c581"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a495838fc974e39c7fd3a85569642c4f184766c11420a1b60b4694590ac7389 · sha256:b05a46756c593376… · /containers/cna/references/1
{"name":"https://github.com/boxlite-ai/boxlite/security/advisories/GHSA-xjhv-pp2r-6f82","tags":["x_refsource_CONFIRM"],"url":"https://github.com/boxlite-ai/boxlite/security/advisories/GHSA-xjhv-pp2r-6f82"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a495838fc974e39c7fd3a85569642c4f184766c11420a1b60b4694590ac7389 · sha256:b05a46756c593376… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/boxlite-ai/boxlite/security/advisories/GHSA-xjhv-pp2r-6f82"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a495838fc974e39c7fd3a85569642c4f184766c11420a1b60b4694590ac7389 · sha256:b05a46756c593376… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.