Skip to content

v5.15.2 - security fixes

Choose a tag to compare

@Jovancoding Jovancoding released this 27 Sep 20:39
· 2 commits to main since this release

Security fixes

  • GHSA-9p2w-prp8-5722 (High) - ClaudeHookBridge deny patterns now inspect every string field of tool_input (e.g. Write.content, Edit.new_string, MCP tool arguments), not just the first candidate field. Over-nested or oversized inputs fail closed. Reported by zx (Jace) / @manus-use.
  • GHSA-hr6v-mfxm-4438 (Moderate) - DashboardServer now validates the Host header (blocks DNS rebinding) and the WebSocket Origin (blocks cross-site WebSocket hijacking). New allowedHosts / allowedOrigins options for proxied deployments. Reported by zx (Jace) / @manus-use.
  • GHSA-4pvg-m42h-c3x2 (Low) - McpSseServer reflects a localhost CORS Origin only when bound to a loopback address. Reported via Sebastion AI (@andesyteoss).
  • CodeQL #180 (js/regex-injection) - hook deny/allow regexes are validated at construction (invalid, oversized, or nested-quantifier patterns rejected); network-ai hook pre-tool-use exits 2 on any error so a bad rule blocks instead of silently allowing.
  • CodeQL #179 (js/incomplete-sanitization) - scripts/clawhub-publish.js rejects arguments cmd.exe cannot safely quote and no longer uses a shell on non-Windows platforms.

Behaviour changes

  • Deny patterns now also see file contents and tool arguments, so a rule like --deny "rm -rf" will block writing a file that contains rm -rf.
  • A DashboardServer behind a reverse proxy with a different hostname must set allowedHosts / allowedOrigins.

CI / maintenance

  • OpenSSF Scorecard: ossf/scorecard-action v2.4.4 (image moved from gcr.io to ghcr.io).
  • Examples load dotenv via its typed main entry (dotenv 18 compatibility).

3,673 tests across 41 suites.


Full changelog: https://github.com/Jovancoding/Network-AI/blob/main/CHANGELOG.md