PT-2026-71443 · Unknown · Network-Ai
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Network-AI versions prior to 5.15.1
Description
A security matcher bypass exists because
SandboxPolicy evaluates raw command strings with quotes preserved, whereas the executor tokenizes commands by stripping quotes before execution. This discrepancy allows attackers to craft quoted commands that evade blocklist checks and approval gates, while the executor subsequently runs the dangerous unquoted argv (argument vector).Recommendations
Update Network-AI to version 5.15.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Network-Ai