TypeScript/Node.js Multi-Agent Orchestrator Vulnerability in Network-AI
CVE-2026-46701

7.6HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-46701?

The Network-AI application is vulnerable due to its MCP SSE server defaulting to an empty secret prior to version 5.4.5. As a result, any request will pass the authorization check unconditionally. This vulnerability allows an unauthenticated attacker to exploit weaknesses in the application by luring users to a malicious webpage. The _handleRequest function’s configuration permits cross-origin requests without restrictions, enabling access to all 22 exposed MCP tools such as config_set, agent_spawn, and blackboard_write. Users are advised to upgrade to version 5.4.5 to mitigate this issue.

Affected Version(s)

Network-AI < 5.4.5

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.