#jovancoding
🚨 EUVD-2026-37787
📊 9.1/10
🏢 Jovancoding

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37787

#cybersecurity #infosec #cve #euvd
June 17, 2026 at 10:00 PM
🚨 EUVD-2026-46034
📊 7.1/10
🏢 Jovancoding

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifes...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46034

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 6:00 PM
🚨 EUVD-2026-46020
📊 5.9/10
🏢 Jovancoding

📝 Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46020

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 6:00 PM
🚨 EUVD-2026-46003
📊 9.9/10
🏢 Jovancoding

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`Sand...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46003

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 6:00 PM
🚨 EUVD-2026-46019
📊 7.6/10
🏢 Jovancoding

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty secret (`process.env['NET...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46019

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 6:00 PM
🚨 EUVD-2026-46005
📊 6.1/10
🏢 Jovancoding

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup ...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46005

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 6:00 PM
🚨 EUVD-2026-46016
📊 5.5/10
🏢 Jovancoding

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46016

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 6:00 PM
🚨 EUVD-2026-46018
📊 6.5/10
🏢 Jovancoding

📝 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sa...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46018

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 6:00 PM
🚨 EUVD-2026-45938
📊 8.8/10
🏢 Jovancoding

📝 Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accept...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45938

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 2:00 PM
🚨 EUVD-2026-45937
📊 9.3/10
🏢 Jovancoding

📝 Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox G...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45937

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 2:00 PM
CVE-2026-64622 - network-ai
Network-AI versions 5.12.2 through 5.13.3 allow anyone to access sensitive approval request information without a password. This is a security risk because it could allow…

Too many irrelevant or confusing CVEs? Use stackflag.com

#networkai #jovancoding #CVE #infosec
CVE-2026-64622: Network-AI 5.12.2-5.13.3: Unauthenticated Access to Approval Details
Network-AI versions 5.12.2 through 5.13.3 allow anyone to access sensitive approval request information without a password.
stackflag.com
July 20, 2026 at 12:28 PM
Jovancoding/Network-AI 5.8.2 fixes 2 security issues
Enhances security by masking tokens and blocking prompt injection, with a new --force
Upgrade carefully.

→ releaseport.com/r/jovancoding-network-ai/v5-8-2
Jovancoding/Network-AI v5.8.2
Masked tokens + blocked prompt injection
releaseport.com
May 28, 2026 at 2:04 AM