Back to overview

CVE-2026-47128

MEDIUM Exploitation: PoC
6.1
CVSS 3.1
Description
nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. Version 0.55.0 patches the issue.

Metadata

CVE ID
CVE-2026-47128
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-05-18 19:50 UTC
Published
2026-07-20 21:46 UTC
Last updated
2026-07-21 12:56 UTC
Primary CWE
CWE-863
CWE-863: Incorrect Authorization
Vendor / Product
always-further / nono
Sources
cve.org  ·  NVD

Severity & Metrics

6.1 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
always-further nono < 0.55.0
Weakness (CWE)
CWESourceDescription
CWE-863 cna CWE-863: Incorrect Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.1 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
References (1)
Back to overview