TypeScript/Node.js Multi-Agent Orchestrator Vulnerability in Network-AI
CVE-2026-46701
7.6HIGH
What is CVE-2026-46701?
The Network-AI application is vulnerable due to its MCP SSE server defaulting to an empty secret prior to version 5.4.5. As a result, any request will pass the authorization check unconditionally. This vulnerability allows an unauthenticated attacker to exploit weaknesses in the application by luring users to a malicious webpage. The _handleRequest function’s configuration permits cross-origin requests without restrictions, enabling access to all 22 exposed MCP tools such as config_set, agent_spawn, and blackboard_write. Users are advised to upgrade to version 5.4.5 to mitigate this issue.
Affected Version(s)
Network-AI < 5.4.5
