Security Advisory

CVE-2026-73614

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-13 11:28:17
Last updated 2026-08-14 16:52:37
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands.