CVE-2026-27597Disclosure(agentfront / enclave)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch agentfront enclave systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enclave

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • Peaked 2d ago at 8 mentions (2026-02-25); latest day: 1
  • 10 total mentions across 3 days

Affected systems

Vendors
Products
enclave

Deep dive

Activity timeline10 mentions / 3d
02468Mentions · 2026-02-25: 8Mentions · 2026-03-02: 1Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-26: 1Patch / Workaround · 2026-02-25: 3Technical Details · 2026-02-25: 7Technical Details · 2026-03-02: 1Technical Details · 2026-05-26: 102-2503-0205-26
Signal classification2 categories
Disclosure
880.0%
Patch
220.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-258
Disclosure6Patch2
2026-03-021
Disclosure1
2026-05-261
Disclosure1
Full discourse10 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27597 (CVSS:10.0, CRITICAL) is Analyzed. Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possibl..https://nvd.nist.gov/vuln/detail/CVE-2026-27597 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27597, noting its critical severity and affected Enclave sandbox version, but provides no exploit or mitigation details.

    1001035
    173 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical sandbox escape vulnerability in #Enclave VM. CVE-2026-27597 CVSS: 10. A threat actor can exploit it to achieve remote code execution on the underlying host. #RCE! #Patch #Patch #Patch

    Post summary

    A critical sandbox escape vulnerability (CVE-2026-27597) with CVSS 10 is disclosed, enabling remote code execution on the host, but no PoC, exploit, or patch details are provided.

    01000184
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27597 Remote Code Execution in Enclave JavaScript Sandbox Before Version 2.11.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27597

    Post summary

    A new CVE (CVE-2026-27597) has been disclosed, indicating a remote code execution vulnerability in Enclave JavaScript Sandbox versions prior to 2.11.1.

    0001054
    4.0K followersView on X
  • Julio Elizondo@jelizor
    Disclosure

    In May 2026 the concept of a "secure sandbox for AI agents" was demolished seven times in thirty days. vm2, the most widely used JavaScript library for isolating AI-generated code, received three critical CVEs in rapid succession. The most severe, CVE-2026-26956 (CVSS 9.8), exploits WebAssembly exception handling to completely bypass the library's code transformer. A host error object escapes into the sandbox without sanitization, the attacker walks up the constructor chain to the Node.js process object, arbitrary command execution on the host. Public proof of concept. The other two, CVE-2026-43999 (CVSS 9.9) and CVE-2026-45411 (CVSS 9.8), complete the picture. The maintainers declared vm2 officially deprecated and discontinued, stating that architectural limitations make it impossible to keep up with changes to the V8 engine. Not a missed patch. An admission of impossibility. Enclave, the sandbox designed specifically to replace vm2 and offer "safe AI agent code execution", fell to CVE-2026-27597. CVSS 10.0, the maximum possible score. PraisonAI, a multi-agent framework: CVE-2026-39888, CVSS 9.9. The sandbox in subprocess mode blocks 11 attributes. The direct execution path blocks 30. The four attributes needed for frame traversal are absent. n8n, a workflow automation platform used in hundreds of thousands of enterprise instances: CVE-2026-25049, CVSS 9.8. Any authenticated user takes complete control of the server. Credentials, API keys, AI pipelines hijackable. NousResearch hermes-agent: CVE-2026-9368. Sandbox escape via environment variable handler. Public exploit. The vendor never responded to the disclosure. The pattern is the same in every case. Prompt becomes code, code runs in a sandbox, sandbox fails, the attacker is on the host. Seven different products, five languages, same sequence. If you are building autonomous agents that generate and execute code, look at these numbers carefully. The sandbox you are probably relying on either no longer exists or has a CVSS above 9. #TheAgentProblem #AISecurity #Agents

    Post summary

    The post details a series of high‑severity sandbox escape vulnerabilities across multiple AI and automation frameworks, providing technical CVSS scores and public PoCs, but no evidence of active exploitation or published patches.

    0000070
    27 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27597: Breaking the Enclave: How JavaScript Coercion Shattered a Sandbox In the world of AI agents, executing untrusted code is a necessary evil. @enclave-vm/core promised a 'secure' environment to run this code, wrapping standard JavaScript ... https://cvereports.com/reports/CVE-2026-27597

    Post summary

    The article announces CVE‑2026‑27597, describing a sandbox escape via JavaScript coercion in enclave‑vm/core, but provides no PoC, exploit, or patch details.

    0000042
    31 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『It is possible to escape the security boundraries set by @ enclave-vm/core, which can be used to achieve remote code execution (RCE).』 CVE-2026-27597 Sandbox Escape in `@ enclave-vm/core` · Advisory · agentfront/enclave · GitHub https://github.com/agentfront/enclave/security/advisories/GHSA-f229-3862-4942

    Post summary

    An advisory reports a sandbox escape in enclave-vm/core that could lead to remote code execution, but no PoC, exploit, or patch details are provided.

    00000369
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27597 Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@… https://www.cve.org/CVERecord?id=CVE-2026-27597

    Post summary

    CVE-2026-27597 exposes a sandbox escape in Enclave before version 2.11.1, which is presumably fixed in that release.

    00000104
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27597: CRITICAL] Stay secure with Enclave! Update to version 2.11.1 to fix a vulnerability allowing remote code execution. Keep your AI agent code safe with the latest security measures.#cve,CVE-2026-27597,#cybersecurity https://cvefind.com/CVE-2026-27597

    Post summary

    The post announces CVE‑2026‑27597 as a critical remote code execution flaw and urges users to update to version 2.11.1 to mitigate the issue.

    0000051
    584 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    680 CRITICAL: CVE-2026-27597 in agentfront enclave (<2.11.1) lets attackers escape JS sandbox & run remote code6a8. Patch to 2.11.1+ now! Full system compromise risk. https://radar.offseq.com/threat/cve-2026-27597-cwe-94-improper-control-of-generati-c298fcde #OffSeq #CVE20262... https://t.co/TIiZkY4s7a

    Post summary

    CVE-2026-27597 is a critical remote code execution flaw in agentfront enclave, patched in version 2.11.1+, with no evidence of active exploitation or PoC provided.

    0000035
    270 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27597** pertains to a critical security flaw in the Enclave JavaScript sandbox, specifically prior to version 2.11.1. Enclave is designed to securely execute AI agent code within a sandboxed environment, preventing malicious code from escaping the security boundaries. However, due to a vulnerability in earlier versions, an attacker could exploit this flaw to escape the sandbox boundaries, leading to **remote code execution (RCE)**. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27597

    Post summary

    The post announces CVE-2026-27597, a critical sandbox escape vulnerability in Enclave JavaScript that permits remote code execution, but it offers no PoC, exploitation details, or mitigation information.

    0000042
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appagentfrontenclave-node.js-

Explore more