VYPR
Vendor

Agentfront

Products
3
CVEs
5
Across products
6
Status
Private

Products

3

Recent CVEs

5
  • CVE-2026-27597CriFeb 25, 2026
    risk 0.58cvss 10.0epss 0.01

    Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version…

  • CVE-2026-22686CriJan 14, 2026
    risk 0.58cvss 10.0epss 0.01

    Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool…

  • CVE-2026-67531CriAug 6, 2026
    risk 0.53cvss epss 0.00

    FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own…

  • CVE-2026-25533HigFeb 6, 2026
    risk 0.50cvss 8.8epss 0.00

    Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed with dynamic property accesses, the hardening of the error objects does not…

  • CVE-2026-39885HigApr 8, 2026
    risk 0.42cvss 7.5epss 0.00

    FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom…