CVE-2026-54051: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Jovancoding Network-AI
Network-AI versions prior to 5.9.1 contain an OS command injection vulnerability due to improper neutralization of special shell characters in the agent sandbox's command allowlist. The allowlist matches whole command strings with wildcards but executes them via a shell, allowing attackers to append arbitrary commands. This issue is fixed in version 5.9.1 by changing execution to a non-shell spawn with strict rejection of unquoted shell metacharacters. Users should upgrade to 5.9.1 or later and avoid broad wildcard allowlist entries.
AI Analysis
Technical Summary
CVE-2026-54051 is an OS command injection vulnerability in Jovancoding's Network-AI prior to version 5.9.1. The agent sandbox uses an allowlist that glob-matches entire command strings, but executes commands through '/bin/sh -c'. This allows wildcard patterns like 'git *' or 'npm *' to match commands with appended shell metacharacters (e.g., 'git status; <anything>'), enabling arbitrary command execution. The vulnerability is addressed in version 5.9.1 by switching to spawn execution without a shell and by rejecting unquoted shell metacharacters before allowlist matching. The fix prevents shell injection by parsing arguments properly and enforcing stricter command validation.
Potential Impact
An attacker with limited privileges can exploit the allowlist wildcard matching combined with shell execution to run arbitrary OS commands, leading to full compromise of confidentiality, integrity, and availability of the affected system. The CVSS score of 9.9 reflects critical impact with network attack vector, low complexity, and no user interaction required.
Mitigation Recommendations
Upgrade Network-AI to version 5.9.1 or later, where the vulnerability is fixed by eliminating shell execution and enforcing strict command tokenization. Additionally, avoid using broad wildcard allowlist entries such as 'node *' or 'npm *' as they inherently allow arbitrary code execution by design. No other vendor advisories or patches are indicated; users should rely on the official upgrade.
CVE-2026-54051: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Jovancoding Network-AI
Description
Network-AI versions prior to 5.9.1 contain an OS command injection vulnerability due to improper neutralization of special shell characters in the agent sandbox's command allowlist. The allowlist matches whole command strings with wildcards but executes them via a shell, allowing attackers to append arbitrary commands. This issue is fixed in version 5.9.1 by changing execution to a non-shell spawn with strict rejection of unquoted shell metacharacters. Users should upgrade to 5.9.1 or later and avoid broad wildcard allowlist entries.
CVSS v3.1
Score 9.9critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54051 is an OS command injection vulnerability in Jovancoding's Network-AI prior to version 5.9.1. The agent sandbox uses an allowlist that glob-matches entire command strings, but executes commands through '/bin/sh -c'. This allows wildcard patterns like 'git *' or 'npm *' to match commands with appended shell metacharacters (e.g., 'git status; <anything>'), enabling arbitrary command execution. The vulnerability is addressed in version 5.9.1 by switching to spawn execution without a shell and by rejecting unquoted shell metacharacters before allowlist matching. The fix prevents shell injection by parsing arguments properly and enforcing stricter command validation.
Potential Impact
An attacker with limited privileges can exploit the allowlist wildcard matching combined with shell execution to run arbitrary OS commands, leading to full compromise of confidentiality, integrity, and availability of the affected system. The CVSS score of 9.9 reflects critical impact with network attack vector, low complexity, and no user interaction required.
Mitigation Recommendations
Upgrade Network-AI to version 5.9.1 or later, where the vulnerability is fixed by eliminating shell execution and enforcing strict command tokenization. Additionally, avoid using broad wildcard allowlist entries such as 'node *' or 'npm *' as they inherently allow arbitrary code execution by design. No other vendor advisories or patches are indicated; users should rely on the official upgrade.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-11T18:24:35.096Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5e50312a4a8d59895ee3c8
Added to database: 07/20/2026, 16:43:29 UTC
Last enriched: 07/30/2026, 12:52:04 UTC
Last updated: 09/04/2026, 10:52:10 UTC
Views: 92
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.