Arbitrary Command Execution in Network-AI by Jovancoding
CVE-2026-54051
9.9CRITICAL
What is CVE-2026-54051?
The Network-AI product by Jovancoding has a vulnerability that permits arbitrary command execution due to insecure handling of shell commands in the agent sandbox. Before version 5.9.1, the sandbox's command allowlist could be bypassed, enabling adversaries to execute unintended shell commands by exploiting wildcard entries. This issue is addressed in version 5.9.1, where command execution is secured by modifying how shell commands are processed, disallowing unquoted metacharacters and enhancing the overall security of the command execution process. Users are encouraged to upgrade to the latest version to mitigate potential security risks.
Affected Version(s)
Network-AI < 5.9.1
