Arbitrary Command Execution in Network-AI by Jovancoding
CVE-2026-54051

9.9CRITICAL

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-54051?

The Network-AI product by Jovancoding has a vulnerability that permits arbitrary command execution due to insecure handling of shell commands in the agent sandbox. Before version 5.9.1, the sandbox's command allowlist could be bypassed, enabling adversaries to execute unintended shell commands by exploiting wildcard entries. This issue is addressed in version 5.9.1, where command execution is secured by modifying how shell commands are processed, disallowing unquoted metacharacters and enhancing the overall security of the command execution process. Users are encouraged to upgrade to the latest version to mitigate potential security risks.

Affected Version(s)

Network-AI < 5.9.1

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.