What is CVE-2026-67531?
CVE-2026-67531 is a critical vulnerability in the FrontMCP framework where the sandboxed `codecall:execute` tool exposes host Zod schema instances via the `_zod` property, potentially allowing sandbox escape. It affects versions prior to 1.5.7, and immediate patching is required.
Azərbaycanca: CVE-2026-67531 FrontMCP frameworkündə kritik zəiflikdir. Bu, `codecall:execute` alətində zəif sandboxing səbəbilə Zod sxem nümunələri vasitəsilə host mühitə icazəsiz çıxış imkanı yaradır. 1.5.7 versiyasına qədər təsir edir, istifadəçilər dərhal yeniləməlidir.
FAQ2
Which framework does CVE-2026-67531 affect?
CVE-2026-67531 affects the FrontMCP framework.
What version should be patched to fix CVE-2026-67531?
It is recommended to update the FrontMCP framework to version 1.5.7 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.