In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Access Control Bypass vulnerabilities in an interactive lesson.
Start learningUpgrade nono-py to version 0.10.1 or higher.
nono-py is a Python bindings for nono capability-based sandboxing
Affected versions of this package are vulnerable to Access Control Bypass due to the policy JSON accepting unknown security-sensitive fields and the failure to automatically enforce CapabilitySet.proxy_only when resolving a policy-derived ProxyConfig. An attacker can gain unauthorized network access by crafting policies with unsupported or misspelled restrictions, potentially allowing outbound requests outside the intended proxy allowlist.