CVE-2026-73615 PUBLISHED

Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch

Assigner: VulnCheck
Reserved: 13.08.2026 Published: 13.08.2026 Updated: 13.08.2026

Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while the executor runs the identical unquoted dangerous argv.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Jovancoding
Product Network-AI
Versions Default: unaffected
  • affected from 0 to 5.15.1 (excl.)
  • Version 5.15.1 is unaffected

Credits

  • manus-use reporter

References

Problem Types

  • Interpretation Conflict CWE