Junglewise Threat Intelligence

nolabs-ai nono-py network sandbox bypass on older Linux kernels

Severity: medium · CVSS 6.4 · Published 2026-06-26

Technologies: nono-py (PyPI). Vendors: PyPI.

Executive brief

nono-py is a Python library used to sandbox AI agents and other untrusted code to prevent them from accessing sensitive network resources. A vulnerability in certain Linux environments allows sandboxed processes to bypass network restrictions and connect directly to unauthorized destinations, such as cloud metadata services. This could lead to the theft of sensitive security credentials or unauthorized data access.

Technical details

A vulnerability exists in nono-py's sandboxed_exec() when using CapabilitySet.proxy_only() on Linux kernels older than 6.7 (which lack Landlock ABI v4 support). In these environments, the Python binding fails to correctly install and supervise the seccomp-notify fallback mechanism intended to enforce proxy-only policies. An attacker with code execution within the sandbox can bypass the proxy by unsetting environment variables (HTTP_PROXY/HTTPS_PROXY) or using raw sockets to establish direct TCP connections. This allows the process to reach restricted endpoints, such as the cloud metadata service (169.254.169.254), potentially leaking IAM credentials. The issue is fixed in version 0.10.1.

Affected products

  • nolabs-ai nono-py >= 0.9.0, < 0.10.1

Timeline

  • 2026-05-23: disclosed
  • 2026-06-26: advisory
  • 2026-06-26: patched: Fixed in version 0.10.1

References

Related threats