Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-81096: ToolUniverse sandbox escape and unauthenticated RCE

ToolUniverse's Python code executor allowed sandbox escape through dunder attribute access, and exposed HTTP/MCP servers with no authentication enabled remote code execution as the server process.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated remote code execution on exposed servers running ToolUniverse versions prior to 1.3.0.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81096