{"id":"CVE-2026-54051","aliases":["GHSA-qw6v-5fcf-5666"],"url":"https://o3.security/vulnerability/CVE-2026-54051","summary":"Network-AI has an an OS Command Injection issue","details":"Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main control against a compromised agent (Adversary 3.2). The allowlist glob-matches the whole command string, but `ShellExecutor` runs that string through `/bin/sh -c`. So any wildcard allow such as `git *`, `npm *` or `node *` also matches `git status; <anything>`, and a scoped command becomes arbitrary execution. The issue is fixed in v5.9.1. `ShellExecutor` now executes via `spawn(file, args, { shell: false })` using a quote-aware parsed argv, so no shell is invoked. `SandboxPolicy.isCommandAllowed` and the new `SandboxPolicy.tokenizeCommand` reject any unquoted shell metacharacter (`; & | $ ` ` ` ( ) < > { }` newline) or unterminated quote before the allowlist glob match; quoted metacharacters are preserved as literal argument data. Users should upgrade to `network-ai@5.9.1` or later. As defense in depth, avoid broad wildcard allowlist entries such as `node *` / `npm *` which are direct code execution by design.","published":"2026-07-20T16:24:20.791Z","modified":"2026-08-12T03:51:24.368974387Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.00666,"percentile":0.49563,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"network-ai","fixedVersion":"5.9.1"}],"fix":{"url":"https://github.com/Jovancoding/Network-AI/commit/379f77656b578144e03415c5b134d8309a4b5792","label":"Jovancoding/Network-AI@379f776"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54051.json"},{"type":"ADVISORY","url":"https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-qw6v-5fcf-5666"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54051"},{"type":"FIX","url":"https://github.com/Jovancoding/Network-AI/commit/379f77656b578144e03415c5b134d8309a4b5792"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.368974387Z"}}