• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cohere ai terrarium sandbox flaw enables root code execution, container

Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape

You are here: Home / General Cyber Security News / Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
April 22, 2026

A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could result in arbitrary code execution.

The vulnerability, tracked as CVE-2026-5752, is rated 9.3 on the CVSS scoring system.

“Sandbox escape vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal,” according to a description of the flaw in CVE.org.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Developed by Cohere AI as an open-source project, Terrarium is a Python sandbox that’s used as a Docker-deployed container for running untrusted code written by users or generated with assistance from a large language model (LLM).

Notably, Terrarium runs on Pyodide, a Python distribution for the browser and Node.js, enabling it to support standard Python packages.  The project has been forked 56 times and starred 312 times.

Cybersecurity

According to the CERT Coordination Center (CERT/CC), the root cause relates to a JavaScript prototype chain traversal in the Pyodide WebAssembly environment that enables code execution with elevated privileges on the host Node.js process.

Successful exploitation of the vulnerability can allow an attacker to break out of the confines of the sandbox and execute arbitrary system commands as root within the container.

In addition, it can permit unauthorized access to sensitive files, such as “/etc/passwd,” reach other services on the container’s network, and even possibly escape the container and escalate privileges further.

It bears noting that the attack requires local access to the system but does not require any user interaction or special privileges to exploit.

Security researcher Jeremy Brown has been credited with discovering and reporting the flaw. Given that the project is no longer actively maintained, the vulnerability is unlikely to be patched.

As mitigations, CERT/CC is advising users to take the following steps –

  • Disable features that allow users to submit code to the sandbox, if possible.
  • Segment the network to limit the attack surface and prevent lateral movement.
  • Deploy a Web Application Firewall to detect and block suspicious traffic, including attempts to exploit the vulnerability.
  • Monitor container activity for signs of suspicious behavior.
  • Limit access to the container and its resources to authorized personnel only.
  • Use a secure container orchestration tool to manage and secure containers.
  • Ensure that dependencies are up-to-date and patched.

“The sandbox fails to adequately prevent access to parent or global object prototypes, allowing sandboxed code to reference and manipulate objects in the host environment,” SentinelOne said. “This prototype pollution or traversal technique bypasses the intended security boundaries of the sandbox.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «systembc c2 server reveals 1,570+ victims in the gentlemen ransomware SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
  • SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
  • 22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP Converters
  • Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023
  • 5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time
  • No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
  • NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
  • Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
  • CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
  • SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files

Copyright © TheCyberSecurity.News, All Rights Reserved.