Executive brief
Network-AI is a tool used for managing AI agents and orchestrating network tasks. A security flaw allows anyone with network access to the service to execute administrative commands without a password. This could allow an attacker to change system settings, create or delete security tokens, and interfere with active AI agents, potentially leading to unauthorized access or disruption of operations.
Technical details
The Model Context Protocol (MCP) HTTP transport in Network-AI fails to implement authentication, session, or token checks in its `_handlePost()` and `handleRPC()` functions. By default, the server binds to `0.0.0.0`, making it reachable over the network. An unauthenticated attacker can send JSON-RPC `tools/call` requests to invoke privileged tools such as `config_set`, `agent_spawn`, and `token_create`. This allows for full enumeration and mutation of the orchestrator's live configuration, agent management, and security token lifecycle. The vulnerability is addressed in version 5.1.3.
Affected products
- Jovancoding Network-AI <= 5.1.2
Timeline
- 2026-04-21: other: Reporter validation date
- 2026-04-24: advisory: GitHub Advisory published
- 2026-05-05: disclosed: CVE-2026-42856 assigned