---
id: CVE-2026-73615
title: >-
  Network-AI versions before 5.15.1 contain a security matcher bypass
  vulnerability where SandboxPolicy evaluates raw command strings with quotes
  preserved while the executor tokenizes commands by stripping quotes before
  execution
summary: >-
  Network-AI versions before 5.15.1 contain a security matcher bypass
  vulnerability where SandboxPolicy evaluates raw command strings with quotes
  preserved while the executor tokenizes commands by stripping quotes before
  execution. Attacke…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-436
published: '2026-08-13'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:36:38.867'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73615'
references:
  - url: >-
      https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-9v4f-j8cv-fhxw
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/network-ai-sandboxpolicy-before-blocklist-bypass-via-quote-mismatch
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-9v4f-j8cv-fhxw
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00654
epssPercentile: 0.49105
ingestedAt: '2026-08-15T23:30:09.234Z'
---

## Overview

Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while the executor runs the identical unquoted dangerous argv.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
