
🚨 Critical - Crabbox Environment Variable Exposure (CVE-2026-8634) Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability. Attackers with access to a malicious or compromised repository can exploit overly permissive environment variable allowlisting to forward local secrets (API tokens, cloud credentials, broker tokens, etc.) into the remote command execution environment. This can lead to credential leakage and potential further compromise. 👉Affected: Crabbox < 0.12.0
Post summary
The text announces CVE-2026-8634, a critical environment variable exposure flaw in Crabbox versions prior to 0.12.0 that could leak credentials from malicious or compromised repositories.

