Skip to content

daytona

v0.186.0 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’

✓ No known CVEs patched in this version

Topics

agentic-workflow ai ai-agents ai-runtime ai-sandboxes code-execution
+2 more
code-interpreter developer-tools

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Updates 🩹 Fixes, ❀️ Thank You, and πŸš€ Features across a mixed release.

Changes in this release

Security High

Restricts object‑storage push‑access ListBucket to caller organization prefix.

Restricts object‑storage push‑access ListBucket to caller organization prefix.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Adds Windows sandbox snapshot and fork API.

Adds Windows sandbox snapshot and fork API.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Shows warning for missing permissions instead of redirect in dashboard UI.

Shows warning for missing permissions instead of redirect in dashboard UI.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Feature Low

Adds wallet error state handling in dashboard UI.

Adds wallet error state handling in dashboard UI.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Dependency Medium

Upgrades react-router to versionβ€―7 in the dashboard.

Upgrades react-router to versionβ€―7 in the dashboard.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Deprecation Medium

Removes obsolete runner class property from API and dashboard.

Removes obsolete runner class property from API and dashboard.

Source: llm_adapter@2026-06-10

Confidence: low

β€”
Bugfix High

Fixes volume ID path traversal vulnerability.

Fixes volume ID path traversal vulnerability.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Closes usage period when desired state is destroyed in API.

Closes usage period when desired state is destroyed in API.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Caches DNS lookups on global HTTP(S) agents to prevent eai_again errors.

Caches DNS lookups on global HTTP(S) agents to prevent eai_again errors.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Bugfix Medium

Resolves organization creation failure due to regionId issue in CLI.

Resolves organization creation failure due to regionId issue in CLI.

Source: llm_adapter@2026-06-10

Confidence: high

β€”
Full changelog

0.186.0 (2026-06-10)

πŸš€ Features

  • api: windows sandbox snapshot and fork (#4911)
  • dashboard: show warning for missing permissions instead of redirect (#4950)
  • dashboard: upgrade react-router to v7 (#4972)
  • docs: sandboxes lifecycle ttl (#4965)
  • guides: CopilotKit guide (#4960)

🩹 Fixes

  • api: close usage period on desired state destroyed (#4962)
  • api: cache dns lookups on global http(s) agents to prevent eai_again errors (#4964)
  • api: scope object-storage push-access ListBucket to caller org prefix (#4966)
  • api: volumeid path traversal bug fix (#4959)
  • api,dashboard: remove obsolete runner class property (#4943)
  • cli: organization create failing due to regionId issue (#4951)
  • dashboard: invite members cta copy tweak (#4925)
  • dashboard: check payment methods instead of wallet (#4947)
  • dashboard: add wallet error state (#4967)
  • opencode: make git sync work on slim sandboxes (#4952)

Chores

  • sync go.sum for v0.185.0 (#4958)
  • migrate workflows to Blacksmith (#4922)
  • docs: add native dep dependencies to dockerfile (#4970)
  • e2e: print runner row from db on propagation failure (#4954)
  • sdk-go: bump to v0.186.0 (#4974)

❀️ Thank You

  • Ante ProjiΔ‡ @aprojic
  • Bruno Grbavac @brunogrbavac
  • Dalin Stone @dalinkstone
  • Goran DraganiΔ‡ @gdraganic
  • Juraj Ε tefaniΔ‡ @stefanicjuraj
  • Luka Brecic @lbrecic
  • Mislav Ivanda @mislavivanda
  • Robert Pavlinic @rpavlini
  • Toma Puljak @Tpuljak
  • tunya @tunyairkad

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track daytona

Get notified when new releases ship.

Sign up free

About daytona

Daytona is a Secure and Elastic Infrastructure for Running AI-Generated Code

All releases β†’

Related context

Earlier breaking changes

  • v0.187.0 api endpoints now require write permission for push access
  • v0.180.0 /api/workspace endpoints are removed; migrate to /api/sandbox equivalents.
  • v0.180.0 GET /api/sandbox now returns paginated response; deprecates /api/sandbox/paginated.

Beta — feedback welcome: [email protected]