{"id":"CVE-2026-47128","aliases":["GHSA-27vp-2mmc-vmh3"],"url":"https://o3.security/vulnerability/CVE-2026-47128","summary":"nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`","details":"nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. Version 0.55.0 patches the issue.","published":"2026-07-20T21:46:32.692Z","modified":"2026-08-12T03:51:29.558003803Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"},"epss":{"score":0.00089,"percentile":0.00478,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"nono-cli","fixedVersion":"0.55.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47128.json"},{"type":"ADVISORY","url":"https://github.com/nolabs-ai/nono/security/advisories/GHSA-27vp-2mmc-vmh3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47128"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.558003803Z"}}