CVE-2026-73615: Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while the executor runs the identical unquoted dangerous argv.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Network-AI SandboxPolicyto a version that resolves this vulnerability.Fixed in 5.15.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73615?
The severity of CVE-2026-73615 is rated high at 8.8 on the CVSS scale.
How do I fix CVE-2026-73615?
To fix CVE-2026-73615, update Network-AI SandboxPolicy to version 5.15.1 or later.
What type of attacks does CVE-2026-73615 allow?
CVE-2026-73615 allows attackers to bypass blocklist checks by crafting specific quoted commands.
What versions of Network-AI are affected by CVE-2026-73615?
Network-AI versions before 5.15.1 are affected by CVE-2026-73615.
What components of Network-AI are involved in CVE-2026-73615?
CVE-2026-73615 involves the SandboxPolicy component of Network-AI.