Executive brief
Network-AI, a library used for managing AI agent permissions and resource access, contains a security flaw in its default configuration. The system fails to properly verify digital signatures, allowing anyone to submit a fake request and claim high-level permissions. An attacker could exploit this to gain unauthorized access to sensitive system resources, including the ability to execute arbitrary shell commands on the host system.
Technical details
An improper cryptographic signature verification vulnerability (CWE-347) exists in the APSAdapter component of Network-AI. By default, the 'local' verification mode uses a fallback verifier that considers any non-empty string to be a valid signature. An unauthenticated remote attacker can exploit this by submitting a forged APS delegation payload with a single-character signature and arbitrary scopes (such as 'shell:exec'). This allows the attacker to bypass signature checks, register forged trust configurations in AuthGuardian, and obtain signed permission-grant tokens for sensitive resources. The issue is fixed in version 5.13.4 by requiring a valid signature function when using local verification mode.
Affected products
- Jovancoding Network-AI < 5.13.4
Timeline
- 2026-07-05: advisory: GitHub Security Advisory GHSA-3jf7-33vc-hgf4 published
- 2026-07-20: disclosed: NVD publication date