CVE advisoryCRITICAL
CVE-2026-67531
FrontMCP Sandbox Escape Allows Remote Code Execution
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
FrontMCP, a framework for Model Context Protocol, has a vulnerability that allows attackers to execute arbitrary code on the server. This occurs because the sandboxed code execution feature incorrectly exposes Zod schema instances, enabling scripts to access the host's Function constructor and run unauthorized commands