CVE-2026-46703
Boxlite Arbitrary File Write Leading to Host RCE via Malicious OCI Image
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
Boxlite, a service for running untrusted code, has a vulnerability allowing a malicious container image to write arbitrary files to the host system, potentially leading to remote code execution. This requires a user to load the crafted image, and the issue is patched in version 0.9.0.