CVE-2026-22686(agentfront / enclave)

LOWCVSS 10.0 · CRITICAL

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, enclave-vm exposes a host-side Error object to sandboxed code. This Error object retains its host realm prototype chain, which can be traversed to reach the host Function constructor. An attacker can intentionally trigger a host error, then climb the prototype chain. Using the host Function constructor, arbitrary JavaScript can be compiled and executed in the host context, fully bypassing the sandbox and granting access to sensitive resources such as process.env, filesystem, and network. This breaks enclave-vm’s core security guarantee of isolating untrusted code. This vulnerability is fixed in 2.7.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enclave

Affected systems

Vendors
Products
enclave

Deep dive

Full discourse2 posts
  • ExploitGrid@exploitgrid

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-22686 CVE-2026-5430 CVE-2026-86218 CVE-2026-12793 CVE-2026-12793 ..🧵👇

    1000139
    42 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-22686 [CRITICAL/PoC] CVE-2026-22686-RemoteCodeExecution-RCE-PoC 🔗 https://exploitgrid.net/exploits/eb125604-2d18-4d5f-95d2-cee638f66421

    1000040
    42 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appagentfrontenclave-node.js-

Explore more