Vendor
Security Matcher Bypass in Network-AI
1 TTP 1 CVENetwork-AI versions prior to 5.15.1 are vulnerable to a command injection bypass where inconsistent quote handling between SandboxPolicy and the executor allows attackers to evade blocklist checks.
Security Bypass in Network-AI ClaudeHookBridge via Input Truncation
1 TTP 1 CVECVE-2026-73614 in ClaudeHookBridge allows attackers to bypass security deny-lists by appending malicious command strings beyond a 500-character truncation threshold, resulting in potential arbitrary code execution.
Authorization Bypass in Network-AI npm Package CVE-2026-64622
1 rule 2 TTPs 1 CVENetwork-AI (npm: network-ai) versions 5.12.2 through 5.13.3 are vulnerable to an authorization bypass (CVE-2026-64622) that allows unauthenticated actors to access sensitive approval request details via specific GET read routes like /approvals/. This vulnerability discloses critical information such as shell-command strings, file paths, justifications, and risk levels. Additionally, a hardcoded 'Access-Control-Allow-Origin: *' header in responses facilitates cross-origin data disclosure, enabling potential exfiltration from malicious websites an operator might visit.