← Back to CVE search

CVE-2026-73614

Network-AI ClaudeHookBridge

Description

Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator-s hard-deny list and execute arbitrary commands.

CVSS 8.8EPSS 0.358%Risk 0.91
View source
Published
2026-08-13 12:17:26
Affected versions
<5.15.1
Type
Library
Last modified
2026-08-13 13:19:19
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H