Vulnerability Description
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-743h-jr5x-mpc
- https://www.vulncheck.com/advisories/network-ai-claudehookbridge-deny-pattern-by
- https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-743h-jr5x-mpc
FAQ
What is CVE-2026-73614?
CVE-2026-73614 is a vulnerability with a CVSS score of 8.8 (HIGH). Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position ...
How severe is CVE-2026-73614?
CVE-2026-73614 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73614?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.