Impact
Network-AI before version 5.13.4 holds an improper cryptographic signature verification flaw in its APSAdapter component. The default local verifier mistakenly accepts any non‑empty string as a valid signature, allowing an attacker to forge APS delegation payloads with arbitrary scopes. By submitting such forged payloads, an attacker can obtain signed permission‑grant tokens that authorize sensitive actions, including the execution of shell commands. This weakness, classified as CWE‑347, directly enables unauthorized privilege escalation and remote code execution.
Affected Systems
The vulnerability affects all builds of Jovancoding Network-AI released prior to version 5.13.4. No specific sub‑version details are listed, so any build earlier than 5.13.4 is considered impacted.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity. Based on the description, it is inferred that the attack vector is network‑based; an unauthenticated attacker can craft and transmit forged APS delegation payloads over the network to the APSAdapter endpoint without needing prior authentication. The EPSS score is < 1%, signalling a low but non‑zero exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. Despite the low EPSS, the potential for obtaining privileged tokens and executing arbitrary commands means the risk remains substantial for any environment where Network‑AI is exposed to untrusted traffic.
OpenCVE Enrichment