nono Sandbox Escape via Unix Domain Socket Access
The nono AI agent sandbox software prior to version 0.55.0 allowed access to local Unix domain sockets, enabling sandbox escape through the systemd dbus socket. Version 0.55.0 patches the vulnerability.
Disclosed 20 July 2026 · Record updated 13 September 2026
Impact
Attackers could escape the sandbox environment through Unix domain socket access to systemd dbus
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47128
