Vendor
CVE-2026-64623: Jovancoding Network-AI Signature Verification Bypass Leading to Remote Code Execution
4 TTPs 1 CVEJovancoding Network-AI versions before 5.13.4 are vulnerable to an improper cryptographic signature verification flaw (CVE-2026-64623) in the APSAdapter component, allowing unauthenticated attackers to bypass signature validation by submitting forged APS delegation payloads with arbitrary scopes to obtain signed permission tokens for sensitive resources, including SHELL_EXEC capabilities.
Network-AI: Improper Neutralization of Special Elements used in an OS Command (CVE-2026-54051)
2 rules 1 TTPThe `network-ai` package, versions prior to 5.9.1, is vulnerable to a critical command injection flaw (CVE-2026-54051) where the `ShellExecutor` component fails to properly neutralize shell metacharacters when processing commands, allowing an attacker to achieve arbitrary command execution as the orchestrator process by bypassing allowlist controls.
Network-AI Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret (CVE-2026-46701)
2 rules 1 TTPNetwork-AI is vulnerable to an unauthenticated cross-origin attack due to an empty default secret and permissive CORS configuration, allowing an attacker to lure a user to a malicious web page and invoke MCP tools like config_set, agent_spawn, and blackboard_write against a default-configured localhost server.
Network-AI Unauthenticated Access to MCP HTTP Endpoint
2 rules 1 TTP 2 IOCsNetwork-AI is vulnerable to missing authentication on the MCP HTTP endpoint, allowing unauthenticated privileged tool calls that could lead to configuration changes and agent manipulation.