Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Network-AI — Vulnerabilities & Security Advisories 11

All 11 CVE vulnerabilities found in Network-AI, with AI-generated Chinese analysis, references, and POCs.

Vendor: Jovancoding

CVE IDTitleCVSSSeverityPublished
CVE-2026-58484 Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning CWE-22 7.1 High2026-07-20
CVE-2026-58482 Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions CWE-352 5.9 Medium2026-07-20
CVE-2026-46701 Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret CWE-346 7.6 High2026-07-20
CVE-2026-58481 Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory CWE-22 6.5 Medium2026-07-20
CVE-2026-58414 Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups CWE-22 5.5 Medium2026-07-20
CVE-2026-58413 EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data CWE-22 6.1 Medium2026-07-20
CVE-2026-54051 Network-AI has an an OS Command Injection issue CWE-78 9.9 Critical2026-07-20
CVE-2026-64622 Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox CWE-862 7.5 High2026-07-20
CVE-2026-64623 Network-AI before 5.13.4 Cryptographic Signature Verification Bypass CWE-347 8.6 High2026-07-20
CVE-2026-48814 Network-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701) CWE-306 9.1 Critical2026-06-17
CVE-2026-42856 Network-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool calls CWE-306--2026-05-11

All 11 known CVE vulnerabilities affecting Network-AI with full Chinese analysis, references, and POCs where available.