Description

Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. Prior to 0.0.16, due to a bug in sandboxing logic, sandbox-runtime did not properly enforce a network sandbox if the sandbox policy did not configure any allowed domains. This could allow sandboxed code to make network requests outside of the sandbox. A patch for this was released in v0.0.16.

INFO

Published Date :

2025-12-04T20:57:20.631Z

Last Modified :

2025-12-05T17:04:34.471Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-66479 vulnerability.

Vendors Products
Anthropic
  • Sandbox-runtime

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability