{"id":"GHSA-9j7f-3r4p-pwh6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-9j7f-3r4p-pwh6","summary":"nono-py vulnerable to authorization bypass / policy confusion","details":"The python API made a restrictive-looking configuration unsafe by default. A caller could configure only reverse-\nproxy credential routes, put the child in CapabilitySet.proxy_only, and reasonably expect network access to be limited\nto those routes. Instead, because empty allowed_hosts meant allow-all inside nono-proxy, the child could use the local\nproxy as a transparent CONNECT tunnel to non-route nominated hosts (not including metadata endpoints).\n\nThat is an authorization bypass / policy confusion issue:\n\n- Intended policy: route-only proxy access.\n- Actual policy: route-only plus arbitrary transparent CONNECT.\n- Boundary crossed: sandboxed child gains broader outbound network reach than the Python policy appears to grant.\n- Impact depends on environment, but it can allow exfiltration or access to unintended internet/internal services\n  through the unsandboxed proxy.\n\nThis should be classified as medium severity by default, potentially high if users rely on route-only configs for strict egress\ncontrol around untrusted code or sensitive credentials. The fix is security-relevant because it changes the default from\nimplicit allow-all to explicit opt-in.","published":"2026-06-26T20:39:43Z","modified":"2026-06-26T20:45:12.257730014Z","cvss":{"score":5.2,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"nono-py","fixedVersion":"0.11.0"}],"fix":{"url":"https://github.com/nolabs-ai/nono-py/commit/163fca083a189967b882d1005bfba099fc9a9d63","label":"nolabs-ai/nono-py@163fca0"},"references":[{"type":"WEB","url":"https://github.com/always-further/nono-py/security/advisories/GHSA-9j7f-3r4p-pwh6"},{"type":"WEB","url":"https://github.com/nolabs-ai/nono-py/commit/163fca083a189967b882d1005bfba099fc9a9d63"},{"type":"PACKAGE","url":"https://github.com/always-further/nono-py"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-26T20:45:12.257730014Z"}}