CVE-2026-27597: Sandbox escape in Enclave AI agent JavaScript sandbox enables RCE
Enclave, a JavaScript sandbox for safe AI agent code execution, contained a flaw in `@enclave-vm/core` before version 2.11.1 that allowed attackers to escape the sandbox security boundaries and achieve remote code execution. The issue was fixed in version 2.11.1.
Disclosed 25 February 2026 · Record updated 13 September 2026
Impact
Escape of the sandbox security boundary could lead to remote code execution on systems running AI agent code in Enclave versions prior to 2.11.1.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27597
