🔴 《严重安全漏洞:CVE-2026-54051》

CVSS 评分: 严重(9.9)  状态: Received  发布时间: 2026-07-20


漏洞描述

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (SandboxPolicy.isCommandAllowed), which THREAT_MODEL.md calls the main control against a compromised agent (Adversary 3.2). The allowlist glob-matches the whole command string, but ShellExecutor runs that string through /bin/sh -c. So any wildcard allow such as git *, npm * or node * also matches git status; <anything>, and a scoped command becomes arbitrary execution. The issue is fixed in v5.9.1. ShellExecutor now executes via spawn(file, args, { shell: false }) using a quote-aware parsed argv, so no shell is invoked. SandboxPolicy.isCommandAllowed and the new SandboxPolicy.tokenizeCommand reject any unquoted shell metacharacter (; & | $ ( ) < > { }newline) or unterminated quote before the allowlist glob match; quoted metacharacters are preserved as literal argument data. Users should upgrade tonetwork-ai@5.9.1or later. As defense in depth, avoid broad wildcard allowlist entries such asnode */npm *` which are direct code execution by design.


🔍 技术细节

字段
CVE ID CVE-2026-54051
CVSS 评分 9.9 🔴
严重程度 严重
CVSS 向量 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE 分类 CWE-78
发布时间 2026-07-20
最后更新 2026-07-20
状态 Received
数据来源 security-advisories@github.com

🔗 参考链接