CVE-2026-8634Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens, cloud credentials, and broker tokens into the remote command environment. Attackers can exploit overly permissive environment variable allowlisting in repo-local Crabbox configuration to serialize sensitive environment variables into remote command execution, exposing credentials to the remote environment.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-15: 2Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 205-15
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Crabbox Environment Variable Exposure (CVE-2026-8634) Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability. Attackers with access to a malicious or compromised repository can exploit overly permissive environment variable allowlisting to forward local secrets (API tokens, cloud credentials, broker tokens, etc.) into the remote command execution environment. This can lead to credential leakage and potential further compromise. 👉Affected: Crabbox < 0.12.0

    Post summary

    The text announces CVE-2026-8634, a critical environment variable exposure flaw in Crabbox versions prior to 0.12.0 that could leak credentials from malicious or compromised repositories.

    00011107
    196 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-8634 — CVSS 9.1/10 █████████░ Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/gt59JLLwhh

    Post summary

    The Tweet announces CVE-2026-8634 as a critical environment variable exposure flaw in Crabbox and confirms that a patch is now available.

    10000105
    39 followersView on X

Explore more