Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
Vulnerability Description
nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an easy sandbox escape by talking to the per-user systemd dbus socket. Version 0.55.0 patches the issue.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Vulnerability Type
授权机制不正确
Vulnerability Title
always-further nono 授权问题漏洞
Vulnerability Description
always-further nono是always-further公司的一款面向 AI Agent 的内核级安全沙箱。 always-further nono 0.55.0之前版本存在授权问题漏洞,该漏洞源于Landlock/seccomp策略允许访问本地Unix域套接字,可能导致攻击者通过与每用户systemd dbus套接字通信轻松实现沙箱逃逸。
CVSS Information
N/A
Vulnerability Type
N/A