HIGHVulnerability

CVE-2026-73615

Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while the executor runs the identical unquoted dangerous argv.

Properties

severity
HIGH
score
8.8
epss_score
0.00364
cve_id
CVE-2026-73615
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-13T12:17:26.337
last_modified
2026-09-09T20:36:38.867
epss_percentile
0.29642

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Interpretation Conflict

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73615 — Ninja Signal Threat Intelligence | Ninja Signal