Cohere AI Sandbox Flaw Allows Root Code Execution

Terrarium was designed to sandbox arbitrary code execution inside Cohere's AI environment. CVE-2026-5752, rated CVSS 9.3, allowed full root code execution and container escape via JavaScript prototype chain traversal. It remains unclear how many sandboxes must be escaped before the industry reconsiders building them.

Severity: Unrated · Category: Supply Chain

Impact: Arbitrary code execution with root privileges, container escape

Source: The Hacker News · Apr 22 2026

How Fencio prevents this

The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.

Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.

All incidents