THREAT OPS › Threat News › [GHSA] GHSA-2j9v-p4xj-cjw2 (high) — Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
[GHSA] GHSA-2j9v-p4xj-cjw2 (high) — Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
GHSA-2j9v-p4xj-cjw2 Severity: high CVE: CVE-2026-53657
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
### Impact On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.
This could result in running an arbitrary command with the root privileges
Indicators of compromise
- 8a45892378d22f40505c31a38f786a07701b6d50sha1
- CVE-2026-53657cve
Original source: https://github.com/advisories/GHSA-2j9v-p4xj-cjw2