THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2j9v-p4xj-cjw2 (high) — Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

[GHSA] GHSA-2j9v-p4xj-cjw2 (high) — Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

highgithub_advisoriesPublished 2026-08-14

GHSA-2j9v-p4xj-cjw2 Severity: high CVE: CVE-2026-53657

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

### Impact On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.

This could result in running an arbitrary command with the root privileges

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2j9v-p4xj-cjw2