network-ai
npm9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting network-aipage 1 of 1
- CVE-2026-42856HIGHCVSS 8.7EG 8.7✓ Fixed in 5.1.32026-05-11
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no authentication, session, origin, or token check, and dispatches them directly to the orchestra…
- CVE-2026-46701HIGHCVSS 7.6EG 7.6✓ Fixed in 5.4.52026-05-21
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty secret (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` at `bin/mcp-server.ts:89`), which causes `_isAuthorized` (`li…
- CVE-2026-48814CRITICALCVSS 9.1EG 9.1✓ Fixed in 5.7.22026-06-17
Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CV…
- CVE-2026-54051CRITICALCVSS 9.9EG 9.9✓ Fixed in 5.9.12026-06-19
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main control against a comp…
- CVE-2026-58413MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.12.22026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this path exists. It …
- CVE-2026-58414MEDIUMCVSS 5.5EG 5.5✓ Fixed in 5.12.22026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows syml…
- CVE-2026-58481MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.12.22026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox …
- CVE-2026-58482MEDIUMCVSS 5.9EG 5.9✓ Fixed in 5.12.22026-07-20
Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate`…
- CVE-2026-58484HIGHCVSS 7.1EG 7.1✓ Fixed in 5.12.22026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later…
Check whether network-ai is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for network-ai CVEs against the assets you own.
Start Free Scan →