CVE-2026-25533: Sandbox escape in Enclave JavaScript sandbox for AI agent code
Versions of the Enclave (enclave-vm) secure JavaScript sandbox prior to 2.10.1 contain multiple weaknesses — AST sanitization bypass via dynamic property access, incomplete error-object hardening, and Function constructor access via host object references — that allow AI agent code to escape the sandbox. The issue was fixed in version 2.10.1.
Disclosed 6 February 2026 · Record updated 13 September 2026
Impact
Code executed by AI agents inside the sandbox could bypass the sandbox's security layers and reach host objects, undermining safe code execution guarantees.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-25533
