CVE-2026-5752Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.

5.5/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 17 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 16 signals
  • Disclosure: 12 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 6 mentions (2026-04-22); latest day: 1
  • 17 total mentions across 6 days

Deep dive

Activity timeline17 mentions / 6d
02356Mentions · 2026-04-15: 2Mentions · 2026-04-22: 6Mentions · 2026-04-23: 5Mentions · 2026-04-24: 2Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-22: 1Active Exploitation · 2026-04-22: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-22: 6Technical Details · 2026-04-23: 5Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-28: 104-1504-2204-2304-2404-2504-28
Signal classification4 categories
Disclosure
1270.6%
General
317.6%
Active Exploitation
15.9%
PoC
15.9%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure1General1
2026-04-226
Active Exploitation1Disclosure4PoC1
2026-04-235
Disclosure5
2026-04-242
Disclosure1General1
2026-04-251
General1
2026-04-281
Disclosure1
Full discourse17 posts
  • The Hacker News@TheHackersNews
    Disclosure

    ⚠️ A Python sandbox for untrusted code has a 9.3 flaw (CVE-2026-5752). A Pyodide bug enables sandbox escape and root command execution. The project is unmaintained, so the issue remains UNPATCHED. 🔗 Learn more → https://thehackernews.com/2026/04/cohere-ai-terrarium-sandbox-flaw.html

    Post summary

    Pyodide’s CVE-2026-5752 allows sandbox escape leading to root command execution; the flaw is severe (CVSS 9.3) and remains unpatched.

    3223621213.2K
    1.8M followersView on X
  • MB日常@MB_Daily1
    Disclosure

    哇,Cohere Terrarium沙箱漏洞刚爆!CVE-2026-5752,9.3高危,能根执行代码、逃逸容器。AI安全隐患频现,让人捏把汗。 预测未来:职场AI工具普及,云端风险将推自托管热潮。数据自己控,才是王道! 我用Moltbot自托管生活,高效又安心,从不愁泄露。

    Post summary

    The text announces the high‑severity CVE‑2026‑5752 affecting Cohere Terrarium, detailing that it permits code execution and container escape, but does not provide PoC, exploit, or mitigation information.

    7100507694
    1.0K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Pythonベースのサンドボックス「Terrarium」に、任意のコード実行につながる深刻なセキュリティ脆弱性が発見された。この脆弱性(CVE-2026-5752)はCVSSスコア9.3と評価されており、危険性が極めて高い。 これはサンドボックスエスケープの脆弱性であり、JavaScriptプロトタイプチェーントラバーサルを悪用することで、ホストプロセス上でroot権限での任意のコード実行が可能となる。この問題はシステムに重大な影響を及ぼす恐れがある。 https://thehackernews.com/2026/04/cohere-ai-terrarium-sandbox-flaw.html

    Post summary

    A newly disclosed CVE‑2026‑5752 in the Python‑based Terrarium sandbox poses a high‑severity sandbox escape that allows root‑privilege code execution via a JavaScript prototype chain flaw.

    0602333.8K
    14.4K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Cohere Terrarium (CVE-2026-5752) and OpenAI Codex CLI (CVE-2025-59532): a cross-CVE analysis of AI code sandbox escapes https://blog.barrack.ai/pyodide-sandbox-escape-cohere-terrarium-openai-codex/

    Post summary

    The blog post examines the sandbox escape vulnerabilities in Cohere Terrarium (CVE‑2026‑5752) and OpenAI Codex CLI (CVE‑2025‑59532), providing an overview but no actionable exploits, patches, or evidence of active attacks.

    1001022.2K
    158.1K followersView on X
  • /r/netsec@_r_netsec
    General

    Cohere Terrarium (CVE-2026-5752) and OpenAI Codex CLI (CVE-2025-59532): a cross-CVE analysis of AI code sandbox escapes https://blog.barrack.ai/pyodide-sandbox-escape-cohere-terrarium-openai-codex/

    Post summary

    The post introduces a cross‑CVE analysis of AI code sandbox escape vulnerabilities in Cohere Terrarium (CVE‑2026‑5752) and OpenAI Codex CLI (CVE‑2025‑59532) without providing additional technical or exploit details.

    030311.3K
    33.4K followersView on X
  • TheCybersecurity.club@TheCyberse46292
    Disclosure

    Stop scrolling if you use Terrarium. A critical flaw (CVE-2026-5752) lets hackers escape the sandbox and gain root access—full system takeover. Exploit abuses JavaScript prototype chains. Update ASAP or avoid untrusted code. #CyberSecurity #Python #Infosec

    Post summary

    CVE‑2026‑5752 is a newly disclosed critical vulnerability that allows sandbox escape and root takeover via JavaScript prototype chain exploitation, prompting urgent updates or avoidance of untrusted code.

    0001045
    3 followersView on X
  • GdyDigital@Gdy_Digital
    Disclosure

    Critical code execution flaw in Python sandbox Terrarium (CVE-2026-5752), rated 9.3 on CVSS. Allows JavaScript prototype chain traversal for root access. https://thehackernews.com/2026/04/cohere-ai-terrarium-sandbox-flaw.html

    Post summary

    A new critical code‑execution flaw (CVE‑2026‑5752) in the Terrarium sandbox has been disclosed, rated 9.3 CVSS, enabling prototype chain traversal for root access, with no evidence yet of active exploitation or available patches.

    0000059
    92 followersView on X
  • Carlos Fynn@fynn_JourX
    Disclosure

    Legacy exposure keeps paying off for attackers. CVE-2026-5752 turns the Terrarium sandbox into a root-lev… CVE-2026-5752 is a critical sandbox escape in Terrarium that can let untrusted code execute… 🔗 Read → https://invaders.ie/resources/blog/cloud-and-application-security/cve-2026-5752-terrarium-sandbox-root-escape-risk

    Post summary

    The post announces the CVE‑2026‑5752 sandbox escape vulnerability in Terrarium, noting it as a critical flaw that lets untrusted code run with root privileges.

    0000037
    83 followersView on X
  • Lucas@lucasverdan
    Disclosure

    🛑 CVE-2026-5752 turns the Terrarium sandbox into a root-level escape risk CVE-2026-5752 is a critical sandbox escape in Terrarium that can let untrusted code execute… 🔗 Details → https://invaders.ie/resources/blog/cloud-and-application-security/cve-2026-5752-terrarium-sandbox-root-escape-risk

    Post summary

    CVE‑2026‑5752 is a critical sandbox escape in Terrarium that allows untrusted code to run with root privileges, as reported in a blog post.

    0000060
    312 followersView on X
  • Carlo Menegui@SocXAInvaders
    Disclosure

    For defenders, cve-2026-5752 turns the terrarium sandbox into a root-level esc… should move fast. CVE-2026-5752 is a critical sandbox escape in Terrarium that can let untrusted code execute… 🔗 Details → https://invaders.ie/resources/blog/cloud-and-application-security/cve-2026-5752-terrarium-sandbox-root-escape-risk

    Post summary

    The post announces a critical sandbox escape vulnerability (CVE‑2026‑5752) in Terrarium that allows untrusted code to execute with root privileges.

    0000034
    5 followersView on X
  • Techgines@nxtgen579255
    Disclosure

    🚨 CVE-2026-5752 — CVSS 9.3. UNPATCHED. Cohere AI's Terrarium sandbox — built to safely run LLM-generated code — has a critical sandbox escape. An attacker inside the sandbox uses JavaScript prototype chain traversal to reach Node.js internals . https://www.techgines.com/post/cve-2026-5752-terrarium-sandbox-escape-cohere-ai-rce https://t.co/pu2Tg7IguL

    Post summary

    CVE-2026-5752 exposes an unpatched sandbox escape in Cohere AI's Terrarium, allowing attackers inside the sandbox to traverse the JavaScript prototype chain and access Node.js internals, rated CVSS 9.3.

    0000061
    4 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-5752 can escape Cohere AI's Terrarium sandbox via JavaScript prototype chain traversal, gaining root privileges on the host. This enables lateral movement and C2 establishment beyond the initial compromise. Runtime segmentation helps contain such post-breach activity. #ZeroDay #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/cohere-ai-terrarium-sandbox-flaw-cve-2026-5752

    Post summary

    CVE‑2026‑5752 is actively being exploited to escape Cohere AI's Terrarium sandbox via prototype chain traversal, achieving host root and enabling lateral movement; containment measures are discussed.

    00000119
    1.9K followersView on X
  • Zero Day Wire@zerodaywire
    Disclosure

    🚨 Critical Cohere AI Terrarium Sandbox Escape Allows Root Code Execution via JavaScript Prototype Chain Traversal (CVE-2026-5752) 🔗 https://zerodaywire.com/article.html?slug=critical-cohere-ai-terrarium-sandbox-escape-allows-root-code-execution-via-javascript-prototype-chain-traversal-cve-2026-5752 #cybersecurity #infosec #threatintel https://t.co/POFSvROji2

    Post summary

    The post announces a newly disclosed critical vulnerability (CVE-2026-5752) in Cohere AI’s Terrarium sandbox, highlighting prototype chain traversal leading to root code execution, but provides no evidence of exploits, active use, or mitigation steps.

    0000075
    157 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2026-5752: Unpatched Pyodide Sandbox Escape Allows Root Command Execution – Act Now! + Video https://undercodetesting.com/cve-2026-5752-unpatched-pyodide-sandbox-escape-allows-root-command-execution-act-now-video/ Educational Purposes!

    Post summary

    The post announces CVE-2026-5752, a sandbox escape in Pyodide that permits root command execution, and directs readers to a video likely demonstrating the exploit.

    0000050
    497 followersView on X
  • Gergely HANDO@GergelyHANDO
    Disclosure

    Via - @TheHackersNews ⚠️ A Python sandbox for untrusted code has a 9.3 flaw (CVE-2026-5752). A Pyodide bug enables sandbox escape and root command execution. The project is unmaintained, so the issue remains UNPATCHED. #python #exploit #bug #security #sandbox 🔗 Learn more →

    Post summary

    A new high‑severity flaw (CVE-2026-5752) in the unmaintained Pyodide sandbox enables root command execution, with no patch available yet.

    00000112
    195 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5752 Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal. https://www.cve.org/CVERecord?id=CVE-2026-5752 ----- Traducción: CVE-2026-5752 Escape de sandbox V… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑5752, outlining a sandbox escape in Terrarium that permits root‑level code execution through prototype chain traversal, but it does not provide a PoC, exploit code, or mitigation details.

    0000031
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5752 Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal. https://www.cve.org/CVERecord?id=CVE-2026-5752

    Post summary

    The text announces CVE-2026-5752, detailing a sandbox escape in Terrarium that permits root‑level code execution via JavaScript prototype chain traversal, without mentioning PoC, exploitation, or mitigations.

    00000266
    57.2K followersView on X

Explore more