漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Enclave has a sandbox escape via infinite recursion and error objects
Vulnerability Description
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed with dynamic property accesses, the hardening of the error objects does not cover the peculiar behavior or the vm module and the function constructor access prevention can be side-stepped by leveraging host object references. This vulnerability is fixed in 2.10.1.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Vulnerability Type
不可达退出条件的循环(无限循环)
Vulnerability Title
Enclave 安全漏洞
Vulnerability Description
Enclave是AgentFront开源的一个沙箱软件。 Enclave 2.10.1之前版本存在安全漏洞,该漏洞源于AST清理可被动态属性访问绕过,错误对象强化未覆盖vm模块特殊行为,且函数构造器访问预防可通过利用主机对象引用规避。
CVSS Information
N/A
Vulnerability Type
N/A