A critical vulnerability, CVE-2026-81096, has been identified in the ToolUniverse software, specifically within the python_executor_tool plugin. The vulnerability arises from an insufficient sandboxing mechanism that allows attackers to escape the sandbox and execute arbitrary code. The python_code_executor tool in python_executor_tool.py fails to properly restrict attribute lookups, enabling attackers to access restricted modules such as 'process' and 'subprocess'. This vulnerability affects systems running ToolUniverse with the python_executor_tool plugin and requires no authentication to exploit. The CVSS score of 10.0 indicates the highest severity, as this allows complete system compromise. Organizations using the affected software should immediately apply the latest security patches and update their systems to mitigate this risk. Until a patch is applied, users are advised to disable or remove the python_executor_tool plugin to prevent potential exploitation.