PT-2026-21851 · Unknown+1 · @Enclave-Vm/Core+1
C0Rydoras
·
Published
2026-02-25
·
Updated
2026-05-26
·
CVE-2026-27597
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Enclave versions prior to 2.11.1
Description
Enclave is a secure JavaScript sandbox used for safe AI agent code execution. A critical security flaw exists in versions prior to 2.11.1, allowing an attacker to escape the sandbox boundaries and achieve remote code execution (RCE) on the underlying host system. This is possible due to the ability to obtain the native
Object constructor, allowing access to restricted properties and host functions. Two proof-of-concept exploits are described, one leveraging host memory track when a memory limit is set, and another utilizing Node's nodejs.util.inspect.custom symbol when a memory limit is not set. Successful exploitation results in arbitrary command execution on the host, representing a full system compromise.Recommendations
Upgrade to version 2.11.1 or later immediately.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Enclave-Vm/Core
Enclave