GHSA-9j7f-3r4p-pwh6Medium· 5.2▾ Sunlitnono-py vulnerable to authorization bypass / policy confusion
▾ Sunlit zone — Low / medium · no exploitation signal
impact 28.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The python API made a restrictive-looking configuration unsafe by default. A caller could configure only reverse- proxy credential routes, put the child in CapabilitySet.proxy_only, and reasonably expect network access to be limited to those routes. Instead, because empty allowed_hosts meant allow-all inside nono-proxy, the child could use the local proxy as a transparent CONNECT tunnel to non-route nominated hosts (not including metadata endpoints).
That is an authorization bypass / policy confusion issue:
This should be classified as medium severity by default, potentially high if users rely on route-only configs for strict egress control around untrusted code or sensitive credentials. The fix is security-relevant because it changes the default from implicit allow-all to explicit opt-in.
nono-py <= 0.10.1Upgrade to a patched release:
nono-py 0.11.0Connected by shared product, vendor, weakness, or advisory.
GHSA-72w7-mf9g-733pMedium· 6.4nono-py has proxy-only network fallback bypass on older Linux kernels
GHSA-m8j6-rc5x-wv36Medium· 5.2nono-py's policy JSON accepts unknown security fields
CVE-2022-2196Medium· 5.8A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…
CVE-2026-57127Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57148Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57147Critical· 9.8PraisonAI is a multi-agent teams system