logo

Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape

ID: 0fb3957e-4df1-5e83-9ec1-d66883304532

STIX ID: report--0fb3957e-4df1-5e83-9ec1-d66883304532

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A critical CVE-2026-5752 vulnerability in the Terrarium Python/Pyodide sandbox allows JavaScript prototype chain traversal to escape the sandbox and execute arbitrary system commands as root inside containerized environments; CERT/CC and vendors warn this can expose sensitive files, enable lateral movement and possible container escape, and provide mitigations while noting the project is likely unmaintained.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.