Cohere AI Sandbox Flaw Allows Root Code Execution
Terrarium was designed to sandbox arbitrary code execution inside Cohere's AI environment. CVE-2026-5752, rated CVSS 9.3, allowed full root code execution and container escape via JavaScript prototype chain traversal. It remains unclear how many sandboxes must be escaped before the industry reconsiders building them.
Severity: Unrated · Category: Supply Chain
Impact: Arbitrary code execution with root privileges, container escape
Source: The Hacker News · Apr 22 2026
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.