CVE-2026-25533

HIGH

NPM Enclave-vm < 2.10.1 - Infinite Loop

Title source: rule
STIX 2.1

Description

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed with dynamic property accesses, the hardening of the error objects does not cover the peculiar behavior or the vm module and the function constructor access prevention can be side-stepped by leveraging host object references. This vulnerability is fixed in 2.10.1.

Scores

CVSS v3 8.8
EPSS 0.0001
EPSS Percentile 0.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (3)
agentfront/enclave 2.7.0 - 2.10.1
enclave-vm/core 0 - 2.10.1npm
npm/enclave-vm 0npm
Published Feb 06, 2026
Tracked Since Feb 18, 2026