FrontMCP Sandbox Escape via Zod Schema Proxy Invariant
FrontMCP versions prior to 1.5.7 contain a sandbox escape vulnerability in the codecall:execute tool that allows attackers to achieve remote code execution by accessing the host Function constructor through Zod schema instances. The vulnerability can be exploited unauthenticated on unconfigured servers or via prompt injection on authenticated servers.
Disclosed 5 August 2026 · Record updated 13 September 2026
Impact
Remote code execution as the server process, exposing OAuth secrets, JWT secrets, session keys, database credentials, and cloud instance metadata.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-67531
