CRITICAL
agentfront
CVE published 2026-08-06
CVE-2026-67531
CVE-2026-67531 is a critical vulnerability in the FrontMCP framework that allows for remote code execution. The issue arises from the sandboxed codecall:execute tool exposing live host Zod schema instances to scripts, which can be exploited to execute arbitrary code in the server process. This vulnerability is particularly concerning as it can be triggered without human interaction on authenticated server [truncated]