🔐 CVE Alert

CVE-2026-67531

UNKNOWN 0.0

FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force the security membrane to hand back the raw host object, letting a script reach _zod.constr.constructor (the host Function constructor) and execute arbitrary code in the server process. A single tools/call is sufficient to escape the sandbox and achieve remote code execution as the server user, exposing everything the process holds such as OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because the framework's DEFAULT_AUTH_OPTIONS is public mode, an unconfigured server serves this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attackerThis issue is fixed in version 1.5.7.

CWE CWE-94
Vendor agentfront
Product frontmcp
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for agentfront frontmcp

Be the first to know when new unknown vulnerabilities affecting agentfront frontmcp are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

agentfront / frontmcp
< 1.5.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/agentfront/frontmcp/security/advisories/GHSA-mp29-fxh8-92px github.com: https://github.com/agentfront/frontmcp/commit/209cddd19a8d4db0777f725b527818da7df6f67f