{"id":"GHSA-9j7f-3r4p-pwh6","summary":"nono-py vulnerable to authorization bypass / policy confusion","details":"The python API made a restrictive-looking configuration unsafe by default. A caller could configure only reverse-\nproxy credential routes, put the child in CapabilitySet.proxy_only, and reasonably expect network access to be limited\nto those routes. Instead, because empty allowed_hosts meant allow-all inside nono-proxy, the child could use the local\nproxy as a transparent CONNECT tunnel to non-route nominated hosts (not including metadata endpoints).\n\nThat is an authorization bypass / policy confusion issue:\n\n- Intended policy: route-only proxy access.\n- Actual policy: route-only plus arbitrary transparent CONNECT.\n- Boundary crossed: sandboxed child gains broader outbound network reach than the Python policy appears to grant.\n- Impact depends on environment, but it can allow exfiltration or access to unintended internet/internal services\n  through the unsandboxed proxy.\n\nThis should be classified as medium severity by default, potentially high if users rely on route-only configs for strict egress\ncontrol around untrusted code or sensitive credentials. The fix is security-relevant because it changes the default from\nimplicit allow-all to explicit opt-in.","modified":"2026-06-26T20:45:12.257730014Z","published":"2026-06-26T20:39:43Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-1188"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-26T20:39:43Z"},"references":[{"type":"WEB","url":"https://github.com/always-further/nono-py/security/advisories/GHSA-9j7f-3r4p-pwh6"},{"type":"WEB","url":"https://github.com/nolabs-ai/nono-py/commit/163fca083a189967b882d1005bfba099fc9a9d63"},{"type":"PACKAGE","url":"https://github.com/always-further/nono-py"}],"affected":[{"package":{"name":"nono-py","ecosystem":"PyPI","purl":"pkg:pypi/nono-py"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.0"}]}],"versions":["0.1.0","0.10.0","0.10.1","0.2.0","0.3.1","0.4.0","0.4.2","0.5.0","0.6.0","0.7.0","0.7.2","0.8.0","0.9.0","0.9.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.10.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9j7f-3r4p-pwh6/GHSA-9j7f-3r4p-pwh6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}