CVE-2026-64623 is an improper cryptographic signature verification vulnerability in Network-AI before 5.13.4. The APSAdapter local verifier accepts any non-empty string as valid, allowing unauthenticated attackers to submit forged APS delegation payloads and obtain signed permission-grant tokens for sensitive resources like SHELL_EXEC. This vulnerability has a high CVSS score of 8.8, indicating a high sev [truncated]
The Network-AI npm package, specifically versions 5.12.2 through 5.13.3, contains a critical vulnerability. This vulnerability fails to apply the configured authorization check to certain GET read routes, allowing unauthenticated actors to access sensitive approval request details. The affected routes include GET /approvals/?status=all, GET /approvals/:id, GET /approvals/stats, and GET /approvals/sse. The [truncated]
CVE-2026-48814 is a critical vulnerability in Network-AI, a TypeScript/Node.js multi-agent orchestrator. Versions 5.7.1 and earlier are affected by an issue allowing unauthenticated cross-origin MCP tool invocation. This is due to an empty default secret used by the MCP SSE server. Although CVE-2026-46701 partially addressed this issue in version 5.4.5 by restricting CORS to localhost origins, the empty d [truncated]