Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1. | |
| Title | @enclave-vm/core is vulnerable to Sandbox Escape | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-25T03:56:25.927Z
Reserved: 2026-02-20T19:43:14.601Z
Link: CVE-2026-27597
No data.
Status : Received
Published: 2026-02-25T04:16:03.557
Modified: 2026-02-25T04:16:03.557
Link: CVE-2026-27597
No data.
OpenCVE Enrichment
No data.