VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-73614

CVE-2026-73614: Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns,

Published Aug 13, 2026 CVSS 8.7

Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary commands.

Affected AI Products

claude code claude
Get the weekly digest. Every Monday: top AI security stories of the week. Free.