Executive brief
Network-AI is a library used to build AI agents that can perform high-risk operations like executing shell commands or managing budgets. A vulnerability in its 'ApprovalInbox' component allows anyone with network access to bypass the human-in-the-loop safety check. This means an unauthorized person or a malicious website could automatically approve dangerous actions that the AI agent was supposed to hold for human review, potentially leading to unauthorized system commands or data loss.
Technical details
The 'ApprovalInbox' component in 'lib/approval-inbox.ts' exposes a REST API and SSE stream to manage human-in-the-loop approvals for sensitive AI agent operations. The HTTP server implementation in 'httpHandler()' fails to implement any authentication checks and hardcodes 'Access-Control-Allow-Origin: *'. This allows unauthenticated attackers to reach the 'POST /approvals/:id/approve' endpoint. Exploitation can occur via direct network requests if the server is bound to a non-loopback interface, or via Cross-Site Request Forgery (CSRF) if an operator visits a malicious website while the inbox is running on localhost. Successful exploitation allows an attacker to resolve pending 'ApprovalGate' promises, triggering the execution of gated high-risk actions (e.g., shell commands) without legitimate consent. The issue was fixed in version 5.12.2 by introducing a required bearer secret.
Affected products
- Jovancoding network-ai >= 5.0.0, <= 5.12.1
Timeline
- 2026-06-17: other: Vulnerability re-confirmed by reporter
- 2026-06-18: advisory: GitHub Advisory published
- 2026-06-19: patched: Fixed in version 5.12.2