agentfront records
4 published records for vendor agentfront.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-27597Proof of concept | @enclave-vm/core is vulnerable to Sandbox Escapeagentfront · enclave · CWE-94 | Critical10.0 | — | 1.0% | Feb 25, 2026 |
40Plan | CVE-2026-22686Proof of concept | Sandbox Escape via Host Error Prototype Chain in enclave-vmagentfront · enclave · CWE-94 | Critical10.0 | — | 0.8% | Jan 13, 2026 |
30Monitor | CVE-2026-39885No exploit | FrontMCP Affected by SSRF via $ref Dereferencing in Untrusted OpenAPI Specificationsfrontmcp · mcp-from-openapi · CWE-918 | High7.5 | — | 0.4% | Apr 8, 2026 |
25Monitor | CVE-2026-25533No exploit | Enclave has a sandbox escape via infinite recursion and error objectsagentfront · enclave · CWE-835 | Medium6.4 | — | 0.2% | Feb 6, 2026 |
- CVE-2026-2759740Plan
@enclave-vm/core is vulnerable to Sandbox Escape
CriticalCVSS 10.0Proof of conceptEPSS 1%agentfront · enclaveFeb 25, 2026
- CVE-2026-2268640Plan
Sandbox Escape via Host Error Prototype Chain in enclave-vm
CriticalCVSS 10.0Proof of conceptEPSS 1%agentfront · enclaveJan 13, 2026
- CVE-2026-3988530Monitor
FrontMCP Affected by SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications
HighCVSS 7.5No exploitEPSS 0%frontmcp · mcp-from-openapiApr 8, 2026
- CVE-2026-2553325Monitor
Enclave has a sandbox escape via infinite recursion and error objects
MediumCVSS 6.4No exploitEPSS 0%agentfront · enclaveFeb 6, 2026