Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
Modified: 7/21/2026
package
pkg:npm/network-ai
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
Modified: 7/21/2026
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Modified: 7/21/2026
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
Modified: 7/21/2026
Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
Modified: 5/13/2026
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
Modified: 7/8/2026
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Modified: 7/21/2026
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
Modified: 7/21/2026
Network-AI: Improper Neutralization of Special Elements used in an OS Command
Modified: 6/19/2026
Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
Modified: 7/8/2026