PT-2025-49149 · Anthropic · Anthropic Sandbox Runtime
Published
2025-12-04
·
Updated
2025-12-05
·
CVE-2025-66479
CVSS v4.0
1.8
Low
| Vector | AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Anthropic Sandbox Runtime versions prior to 0.0.16
Description
Anthropic Sandbox Runtime is a sandboxing tool designed to enforce filesystem and network restrictions on processes. Prior to version 0.0.16, a flaw in the sandboxing logic allowed sandboxed code to potentially make network requests outside of the intended sandbox environment if the sandbox policy did not define any allowed domains. This occurred because the network sandbox was not properly enforced in such scenarios.
Recommendations
Update to version 0.0.16 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anthropic Sandbox Runtime