Sandbox Escape Vulnerability in Nono Software by Nolabs AI
CVE-2026-47128
6.1MEDIUM
What is CVE-2026-47128?
Nono, a software platform enabling AI agents to run in a zero-latency sandbox, has a vulnerability prior to version 0.55.0 where its Landlock and seccomp policies permit access to local Unix domain sockets. This oversight can facilitate an escape from the sandbox, allowing unauthorized communication with the per-user systemd dbus socket. Users are urged to upgrade to version 0.55.0 or later to mitigate the risks associated with this vulnerability.
Affected Version(s)
nono < 0.55.0
