HIGH 8.7 NVD
CVE-2026-73614
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untr
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands.
References
- https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-743h-jr5x-mpcr
- https://www.vulncheck.com/advisories/network-ai-claudehookbridge-deny-pattern-bypass-via-t
- https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-743h-jr5x-mpcr
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-13 via NVD.
vulnfeed aggregates 10540 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.