VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews ยท rss_64c8458c46d8535c5a5e7719850a4726

Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape

Published Apr 22, 2026
A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-5752, is rated 9.3 on the CVSS scoring system. "Sandbox escape vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal," according to

Affected AI Products

cohere