Junglewise Threat Intelligence

CVE-2026-54323: Daytonaio Daytona improper TLS certificate validation in git clone

CVE-2026-54323 · Severity: medium · CVSS 5.9 · Published 2026-06-23

Technologies: Daytonaio Daytona. Vendors: Daytona.

Executive brief

Daytona, a platform for running AI-generated code, contained a security flaw where it failed to verify the identity of servers when downloading code from Git repositories. An attacker positioned on the network could intercept these connections to steal sensitive Git login credentials or provide malicious code to the system. This could lead to unauthorized access to a user's private code repositories and the execution of tampered code within the Daytona environment.

Technical details

A vulnerability in the Daytona daemon's git clone implementation (affecting both go-git and native git CLI paths) results in the disabling of TLS certificate verification. When a clone request includes credentials, the daemon transmits the HTTP Basic Authorization header over an unvalidated connection. A man-in-the-middle (MitM) attacker can present a spoofed certificate to capture Git personal access tokens or passwords and inject malicious repository content into the sandbox. This issue is specific to the clone operation, as pull and push operations already enforced verification. The vulnerability is addressed in version 0.185.0 by enforcing TLS verification by default.

Affected products

  • Daytonaio Daytona < 0.185.0

Timeline

  • 2026-06-09: advisory: GitHub advisory published by maintainers
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026-06-23: patched: Fix released in version 0.185.0

References

Related threats