Junglewise Threat Intelligence

CVE-2026-58414: Jovancoding Network-AI symlink following in EnvironmentManager backup

CVE-2026-58414 · Severity: medium · CVSS 5.5 · Published 2026-07-20

Technologies: Jovancoding Network-AI. Vendors: Jovancoding.

Executive brief

Network-AI is a multi-agent orchestration tool used to coordinate AI agents and manage their environments. A security flaw in the backup system allows an attacker with local access to trick the software into copying sensitive files from outside the intended environment into a backup folder. This could lead to the unauthorized disclosure of private data or system secrets to anyone who can access the backup files.

Technical details

A symlink following vulnerability exists in the `EnvironmentManager.backup()` function of Network-AI. The `_collectBackupFiles()` helper function utilized `statSync()`, which resolves symbolic links, rather than `lstatSync()`. By placing a malicious symlink within the environment data directory (`data/<env>`), a local attacker with low privileges can cause the backup process to traverse the link and copy arbitrary readable files from the host system into the backup artifact directory. This issue is fixed in version 5.12.2 by switching to `lstatSync()` and explicitly skipping entries where `isSymbolicLink()` is true.

Affected products

  • Jovancoding Network-AI < 5.12.2

Timeline

  • 2026-06-18: patched: Fixed in version 5.12.2 via commit a59c13a
  • 2026-07-20: advisory: GHSA-6x2m-p4xp-wg22 published
  • 2026-07-20: disclosed

References

Related threats