{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/network-ai/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-64622"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Network-AI (npm: network-ai) (versions 5.12.2 through 5.13.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authorization-bypass","information-disclosure","npm"],"_cs_type":"advisory","_cs_vendors":["Network-AI"],"content_html":"\u003cp\u003eCVE-2026-64622 impacts \u003ccode\u003enetwork-ai\u003c/code\u003e npm package versions 5.12.2 through 5.13.3, allowing unauthenticated actors to bypass authorization checks on specific GET read routes related to the \u003ccode\u003eApprovalInbox\u003c/code\u003e. This flaw means that even when a secret is configured, sensitive approval request details become accessible without authentication. The affected routes, including \u003ccode\u003e/approvals/?status=all\u003c/code\u003e, \u003ccode\u003e/approvals/:id\u003c/code\u003e, \u003ccode\u003e/approvals/stats\u003c/code\u003e, and \u003ccode\u003e/approvals/sse\u003c/code\u003e, disclose full \u003ccode\u003eApprovalEntry\u003c/code\u003e content such as action/target shell-command strings, file paths, justifications, and risk levels. Compounding the issue, all responses from these routes carry a hardcoded \u003ccode\u003eAccess-Control-Allow-Origin: *\u003c/code\u003e header, which facilitates cross-origin data disclosure. This allows malicious websites, if visited by an operator, to potentially exfiltrate the exposed sensitive data. This vulnerability represents an incomplete fix for a previously identified issue (GHSA-mxjx-28vx-xjjj).\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a \u003ccode\u003enetwork-ai\u003c/code\u003e instance running vulnerable versions 5.12.2 through 5.13.3.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an unauthenticated HTTP GET request to one of the vulnerable \u003ccode\u003eApprovalInbox\u003c/code\u003e read routes, such as \u003ccode\u003e/approvals/?status=all\u003c/code\u003e, \u003ccode\u003e/approvals/:id\u003c/code\u003e, \u003ccode\u003e/approvals/stats\u003c/code\u003e, or \u003ccode\u003e/approvals/sse\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDue to the CVE-2026-64622 authorization bypass, the \u003ccode\u003enetwork-ai\u003c/code\u003e application fails to apply the configured \u003ccode\u003echeckAuth/secret\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application responds with full \u003ccode\u003eApprovalEntry\u003c/code\u003e content, which includes sensitive data like shell-command strings, file paths, justifications, and risk levels, without requiring authentication.\u003c/li\u003e\n\u003cli\u003eThe response also contains a hardcoded \u003ccode\u003eAccess-Control-Allow-Origin: *\u003c/code\u003e header, making the disclosed data vulnerable to cross-origin access.\u003c/li\u003e\n\u003cli\u003eIf an operator of the \u003ccode\u003enetwork-ai\u003c/code\u003e application visits a malicious website, that website can initiate cross-origin requests to the vulnerable \u003ccode\u003enetwork-ai\u003c/code\u003e instance.\u003c/li\u003e\n\u003cli\u003eThe malicious website successfully retrieves the sensitive approval data and exfiltrates it to an attacker-controlled server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-64622 leads to unauthorized disclosure of highly sensitive information, including critical operational details like shell-command strings, internal file paths, and business justifications for approvals. This exposure can provide attackers with valuable intelligence for further attacks, potentially leading to privilege escalation, system compromise, or data manipulation. The hardcoded \u003ccode\u003eAccess-Control-Allow-Origin: *\u003c/code\u003e header also enables severe privacy and data exfiltration risks, as any visited malicious website could programmatically extract this sensitive data, impacting organizations using the vulnerable versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-64622 by immediately updating the \u003ccode\u003enetwork-ai\u003c/code\u003e npm package to a version outside the affected range (i.e., higher than 5.13.3 or lower than 5.12.2 if applicable).\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect CVE-2026-64622 Exploitation Attempts on Network-AI\u0026quot; to your SIEM solution to alert on suspicious access patterns.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for unauthenticated GET requests to the \u003ccode\u003e/approvals/?status=all\u003c/code\u003e, \u003ccode\u003e/approvals/:id\u003c/code\u003e, \u003ccode\u003e/approvals/stats\u003c/code\u003e, and \u003ccode\u003e/approvals/sse\u003c/code\u003e endpoints, referencing the log source category \u003ccode\u003ewebserver\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to restrict or block unauthenticated access to the \u003ccode\u003enetwork-ai\u003c/code\u003e \u003ccode\u003e/approvals/*\u003c/code\u003e paths mentioned in the attack chain, if not required for legitimate operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T12:31:09Z","date_published":"2026-07-20T12:31:09Z","id":"https://feed.craftedsignal.io/briefs/2026-07-network-ai-auth-bypass/","summary":"Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 are vulnerable to an authorization bypass (CVE-2026-64622) that allows unauthenticated actors to access sensitive approval request details via specific GET read routes like /approvals/. This vulnerability discloses critical information such as shell-command strings, file paths, justifications, and risk levels. Additionally, a hardcoded 'Access-Control-Allow-Origin: *' header in responses facilitates cross-origin data disclosure, enabling potential exfiltration from malicious websites an operator might visit.","title":"Authorization Bypass in Network-AI npm Package CVE-2026-64622","url":"https://feed.craftedsignal.io/briefs/2026-07-network-ai-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Network-AI","version":"https://jsonfeed.org/version/1.1"}