Command Injection Vulnerability in Network-AI ClaudeHookBridge by Jovancoding
CVE-2026-73614
8.7HIGH
What is CVE-2026-73614?
The Network-AI ClaudeHookBridge prior to version 5.15.1 is vulnerable to a command injection flaw. This vulnerability arises due to improper truncation of target strings, limiting them to 500 characters before evaluating deny patterns. As a result, attackers can craft malicious commands that extend beyond this limit, leading to the potential execution of arbitrary commands by bypassing the intended deny list configurations.
Affected Version(s)
Network-AI 0 < 5.15.1
Network-AI 5.15.1
