
In May 2026 the concept of a "secure sandbox for AI agents" was demolished seven times in thirty days. vm2, the most widely used JavaScript library for isolating AI-generated code, received three critical CVEs in rapid succession. The most severe, CVE-2026-26956 (CVSS 9.8), exploits WebAssembly exception handling to completely bypass the library's code transformer. A host error object escapes into the sandbox without sanitization, the attacker walks up the constructor chain to the Node.js process object, arbitrary command execution on the host. Public proof of concept. The other two, CVE-2026-43999 (CVSS 9.9) and CVE-2026-45411 (CVSS 9.8), complete the picture. The maintainers declared vm2 officially deprecated and discontinued, stating that architectural limitations make it impossible to keep up with changes to the V8 engine. Not a missed patch. An admission of impossibility. Enclave, the sandbox designed specifically to replace vm2 and offer "safe AI agent code execution", fell to CVE-2026-27597. CVSS 10.0, the maximum possible score. PraisonAI, a multi-agent framework: CVE-2026-39888, CVSS 9.9. The sandbox in subprocess mode blocks 11 attributes. The direct execution path blocks 30. The four attributes needed for frame traversal are absent. n8n, a workflow automation platform used in hundreds of thousands of enterprise instances: CVE-2026-25049, CVSS 9.8. Any authenticated user takes complete control of the server. Credentials, API keys, AI pipelines hijackable. NousResearch hermes-agent: CVE-2026-9368. Sandbox escape via environment variable handler. Public exploit. The vendor never responded to the disclosure. The pattern is the same in every case. Prompt becomes code, code runs in a sandbox, sandbox fails, the attacker is on the host. Seven different products, five languages, same sequence. If you are building autonomous agents that generate and execute code, look at these numbers carefully. The sandbox you are probably relying on either no longer exists or has a CVSS above 9. #TheAgentProblem #AISecurity #Agents
Post summary
The post announces multiple recent, high‑CVSS sandbox escape CVEs across several AI agent frameworks, noting that public proof‑of‑concept exploits exist and many maintainers have deprecated affected libraries.






