CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53657

highCVSS 8.2covered by 2 sourcesfirst seen 2026-07-10
Impact On an instance of Lima running with qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled. This could result in running an arbitrary command with the root privileges in the VM (not on the host), as lima-guestagent.sock provides the tunneling service for an arbitrary address, including a Unix socket address for privileged daemons like D-Bus. This vulnerability is not exploitable on vz driver, as the guest agent uses vsocks instead of Unix sockets. Patches Patched in Lima v2.1.3 (8a45892378d22f40505c31a38f786a07701b6d50) [!NOTE] The default user account in the VM can still run an arbitrary command as the root via the guest agent socket. This is not a vulnerability, as the user can already run an arbitrary command with sudo by design. Workarounds - On macOS hosts, use vz driver instead of qemu (limactl create --vm-type=vz. Default since v1.0.) - Or, disable the guest agent (limactl create --plain)

⚡ Watch CVE-2026-53657

Get an email if CVE-2026-53657 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-53657

CVE.org record

Embed the live status

CVE-2026-53657 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53657 status](https://www.csirts.com/badge/CVE-2026-53657)](https://www.csirts.com/cve/CVE-2026-53657)