Vulnerability Platform
- AI
POCs
Reproduced
Malicious Packages
Security Intel
Resources
API Docs
Affected Products
Bounty Intel
Stats
About
Search
Upgrade
Settings
English
ไธญๆ
English
ๆฅๆฌ่ช
Theme
Default
Anime Pink
Feeling Rich
Login
Goal Reached
Thanks to every supporter โ we hit 100%!
Goal: 1000 CNY ยท Raised:
1359
CNY
100%
Buy Us a Coffee
Home
CVE-2026-27597
AI Analysis Summary
CVE-2026-27597
โ AI Deep Analysis Summary
Updated May 06, 2026
CVSS 10.0 ยท Critical
This is a
summary
of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1
What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Code Injection in Enclave (AgentFront). ๐ **Consequences**: Security boundary escape โ Remote Code Execution (RCE). Critical integrity loss!
Q2
Root Cause? (CWE/Flaw)
๐ก๏ธ **CWE-94**: Improper Control of Generation of Code (Code Injection). ๐ฅ **Flaw**: Unsafe handling allows escaping `@enclave-vm/core` sandbox boundaries.
Q3
Who is affected? (Versions/Components)
๐ฆ **Vendor**: AgentFront. ๐ฆ **Product**: Enclave. ๐ **Affected**: Versions **< 2.11.1**. โ **Safe**: 2.11.1+.
Q4
What can hackers do? (Privileges/Data)
๐ **Privileges**: Full Remote Code Execution (RCE). ๐ **Data**: Complete compromise (Confidentiality, Integrity, Availability all High).
Q5
Is exploitation threshold high? (Auth/Config)
๐ **Auth**: None (PR:N). ๐ **Network**: Remote (AV:N). ๐ฏ **Complexity**: Low (AC:L). ๐ **Threshold**: VERY LOW. Easy to exploit!
Q6
Is there a public Exp? (PoC/Wild Exploitation)
๐ **Public Exp?**: No PoCs listed in data. โ ๏ธ **Risk**: CVSS 10.0 implies high likelihood of wild exploitation soon. Stay alert!
Q7
How to self-check? (Features/Scanning)
๐ **Check**: Scan for `agentfront/enclave` versions < 2.11.1. ๐ก **Feature**: Look for `@enclave-vm/core` usage. Verify version numbers!
Q8
Is it fixed officially? (Patch/Mitigation)
๐ฉน **Fixed?**: YES. ๐ **Date**: 2026-02-25. ๐ **Patch**: Commit `09afbebe...` on GitHub. Update immediately!
Q9
What if no patch? (Workaround)
๐ง **No Patch?**: Isolate network. ๐ **Mitigate**: Restrict input to Enclave components. ๐ซ **Block**: External access to vulnerable endpoints.
Q10
Is it urgent? (Priority Suggestion)
๐ฅ **Urgency**: CRITICAL (CVSS 10.0). ๐จ **Priority**: PATCH NOW! RCE risk is immediate. Do not delay!
Continue exploring
Vulnerability detail
Full AI analysis (login)
agentfront
CWE-94