Network-AI's ApprovalInbox Vulnerability in TypeScript/Node.js Product
CVE-2026-58482
5.9MEDIUM
What is CVE-2026-58482?
The ApprovalInbox feature in Network-AI allows for HTTP requests without authentication. This exposes the human-in-the-loop Approval Gate mechanism, permitting unauthorized parties to enumerate and approve pending requests, effectively bypassing necessary human consent for executing high-risk operations. The issue is present in versions 5.0.0 to 5.12.1 and is mitigated in version 5.12.2 by introducing an optional secret and requiring authentication for state-changing operations.
Affected Version(s)
Network-AI >= 5.0.0, < 5.12.2
