PT-2026-71442 · Network Ai · Claudehookbridge
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Network-AI ClaudeHookBridge versions prior to 5.15.1
Description
An issue exists where the software truncates the target string to 500 characters before evaluating
denyPatterns, whereas Claude Code executes the full untruncated command. This allows attackers to place malicious content beyond the 500th byte in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands.Recommendations
Update Network-AI ClaudeHookBridge to version 5.15.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Claudehookbridge