Sandbox Escape Vulnerability in Nono Software by Nolabs AI
CVE-2026-47128

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-47128?

Nono, a software platform enabling AI agents to run in a zero-latency sandbox, has a vulnerability prior to version 0.55.0 where its Landlock and seccomp policies permit access to local Unix domain sockets. This oversight can facilitate an escape from the sandbox, allowing unauthorized communication with the per-user systemd dbus socket. Users are urged to upgrade to version 0.55.0 or later to mitigate the risks associated with this vulnerability.

Affected Version(s)

nono < 0.55.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.