Executive brief
Daytona is a platform used to run AI-generated code and manage automated workflows. A security flaw allowed unauthorized individuals to join a business organization by claiming an email address that had a pending invitation, even if they couldn't prove they owned that email. This could allow an attacker to gain full control over a company's workspace, access sensitive configurations, and manage other members if they successfully hijack an invitation intended for a legitimate user.
Technical details
A vulnerability in Daytona's OIDC authentication flow allowed users to accept or decline organization invitations using unverified email addresses. While Daytona matches the invitation's target email against the email in the caller's OIDC token, it failed to enforce an 'email_verified' check on the invitation acceptance path. If an identity provider allows self-service signup and issues sessions before verification, an attacker could register an account with a target's email address and accept a pending invitation. This allows the attacker to join the organization with the role specified in the invitation, potentially up to 'Owner' level. The issue is resolved in version 0.184.0 by requiring verified emails for invitation endpoints.
Affected products
- daytonaio Daytona < 0.184.0
Timeline
- 2026-06-05: advisory: GitHub advisory published by vendor
- 2026-06-23: disclosed: CVE published to NVD