Remote Code Execution Vulnerability in Enclave JavaScript Sandbox by AgentFront
CVE-2026-27597
10CRITICAL
What is CVE-2026-27597?
Enclave, a secure JavaScript sandbox engineered for safe AI agent code execution, has a vulnerability that enables users to escape its security boundaries. This flaw, present in versions prior to 2.11.1, allows for unauthorized remote code execution, posing a significant risk to both data integrity and application security. The issue has been addressed in version 2.11.1, and users are strongly encouraged to update their Enclave installations to mitigate potential threats.
Affected Version(s)
enclave < 2.11.1
