network-ai vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-48X2-6PR9-2JJFMediumnetwork-ai: Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment dataGHSA-6X2M-P4XP-WG22Mediumnetwork-ai: Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backupsGHSA-MXJX-28VX-XJJJMediumnetwork-ai: Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions GHSA-JVCM-F35G-W78PMediumnetwork-ai: Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directoryGHSA-2FMP-9RVW-HC96Highnetwork-ai: Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruningCVE-2026-54051Criticalnetwork-ai: Network-AI: Improper Neutralization of Special Elements used in an OS Command CVE-2026-48814Criticalnetwork-ai: Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requestsCVE-2026-46701Highnetwork-ai: Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default SecretCVE-2026-42856Highnetwork-ai: Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls

Stop the waste.
Protect your environment with Kodem.