Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
npm/network-ai — 9 CVEs · VulnScope
pkg:npm/
network-ai
9 total CVEs
CRITICAL
2
HIGH
2
MEDIUM
4
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.9
CVE-2026-54051
Network-AI: Improper Neutralization of Special Elements used in an OS Command
from 0, < 5.9.1
CRITICAL
9.1
CVE-2026-48814
Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
from 0, < 5.7.2
HIGH
7.6
CVE-2026-46701
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
from 0, < 5.4.5
HIGH
7.1
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
from 0, < 5.12.2
MEDIUM
6.5
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
from 0, < 5.12.2
MEDIUM
6.1
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
from 0, < 5.12.2
MEDIUM
5.9
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
>= 5.0.0, < 5.12.2
MEDIUM
5.5
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
from 0, < 5.12.2
—
Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
from 0, < 5.1.3
CVE-2026-58484
CVE-2026-58481
CVE-2026-58413
CVE-2026-58482
CVE-2026-58414
CVE-2026-42856