Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jovancoding
Jovancoding network-ai |
|
| Vendors & Products |
Jovancoding
Jovancoding network-ai |
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands. | |
| Title | Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation | |
| Weaknesses | CWE-436 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T12:54:21.152Z
Reserved: 2026-08-13T11:16:27.835Z
Link: CVE-2026-73614
Updated: 2026-08-13T12:54:17.756Z
Status : Received
Published: 2026-08-13T12:17:26.197
Modified: 2026-08-13T13:19:19.537
Link: CVE-2026-73614
No data.
OpenCVE Enrichment
Updated: 2026-08-13T12:45:03Z
-
CWE-436
Interpretation Conflict