Skip to content
cyberMEDIUM2026-04-23 00:51 UTC

CVE-2026-5752 — Cohere AI's Terrarium sandbox (used to run LLM-generated code) has a CVSS 9.3 prototype chain escape to root. No patch. Worth discussing the AI infrastructure threat model.

CERT/CC dropped VU#414811 yesterday. Terrarium — Cohere's open-source Python sandbox for running untrusted AI-generated code in Docker — has a critical sandbox escape via JavaScript prototype chain traversal in its Pyodide/WebAssembly runtime. The short version of the exploit path: The mock docume

ORIGINAL SOURCE →via Reddit r/cybersecurity
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber