Verified reproduction
CVE-2026-5674: PipeWire sandbox escape via malicious library loading in PulseAudio compatibility layer
CVE-2026-5674 is verified against the affected target This high reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00309.
Severity HIGH
Confidence HIGH
Reproduced in 88m 8s
Tool calls 286
Spend $9.12
$
pruva-verify REPRO-2026-00309 or
curl -O https://pruva.dev/api/v1/reproductions/REPRO-2026-00309/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh Run in a VM or disposable container. This exploits a real vulnerability.
CVE-2026-5674 is a Linux sandbox escape in PipeWire. Public advisories describe an attacker with minimal permissions inside a sandboxed environment, such as Flatpak, loading a malicious library through PipeWire's PulseAudio compatibility layer to escape the sandbox and execute code outside it.
The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.
Loading session...
Scripts, logs, diffs, and output captured during the reproduction.
bundle/logs/client_fixed_attempt2.log0.4 KBbundle/repro/reproduction_steps.sh16.2 KBbundle/repro/rca_report.md9.4 KBbundle/repro/runtime_manifest.json1.9 KBbundle/logs/client_fixed_attempt1.log0.4 KBbundle/logs/client_vuln_attempt2.log0.4 KBbundle/logs/daemon_fixed_attempt1_pipewire.log1.2 KBbundle/logs/daemon_fixed_attempt1_pulse.log0.9 KBbundle/logs/daemon_fixed_attempt2_pipewire.log1.2 KBbundle/logs/daemon_fixed_attempt2_pulse.log0.9 KBbundle/logs/daemon_vuln_attempt1_pipewire.log1.2 KBbundle/logs/daemon_vuln_attempt1_pulse.log1.8 KBbundle/logs/daemon_vuln_attempt2_pipewire.log1.2 KBbundle/logs/daemon_vuln_attempt2_pulse.log1.8 KBbundle/logs/negative_control_obs_fixed_attempt2.json0.3 KBbundle/logs/ns_client_host_fixed_attempt1.txt0.1 KBbundle/logs/ns_client_host_fixed_attempt2.txt0.1 KBbundle/logs/ns_client_host_vuln_attempt1.txt0.1 KBbundle/logs/ns_client_host_vuln_attempt2.txt0.1 KBbundle/logs/ns_evidence_fixed_attempt1.txt0.3 KBbundle/logs/ns_evidence_fixed_attempt2.txt0.3 KBbundle/logs/ns_evidence_vuln_attempt2.txt0.3 KBbundle/repro/validation_verdict.json1.0 KB