Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Jovancoding — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting Jovancoding. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page details vulnerability aggregation data for the vendor Jovancoding, focusing on common software weakness classifications. It collects and organizes reports concerning security flaws, coding errors, and configuration mistakes associated with products developed or maintained by this entity. The dataset spans historical records from early releases up to the most recent advisories, ensuring a comprehensive view of the security landscape over time. Here, users can track the vendor's security advisory history to identify patterns in patching response times and release cycles. Visitors are able to understand the prevalence and nature of specific weakness classes within the vendor's codebase, such as buffer overflows or injection flaws. Additionally, the resource allows for looking up a product's vulnerability history to assess long-term security stability. By aggregating these diverse data points, the page provides a clear context for evaluating risk. It serves as a reference for security analysts, developers, and auditors who need to review past incidents. The information presented is intended to facilitate informed decision-making regarding supply chain security and remediation priorities. Users can explore how specific vulnerabilities were handled and communicated by the vendor. This structured approach helps in comparing the vendor's security posture against industry standards. The goal is to offer transparency and factual insights without speculation. All entries are sourced from public disclosures and verified reports. This ensures reliability for those conducting due diligence or risk assessments. The content is updated regularly to reflect new findings and corrections.

Top products by Jovancoding: Network-AI
CVE IDTitleCVSSSeverityPublished
CVE-2026-58484 Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning — Network-AICWE-22 7.1 High2026-07-20
CVE-2026-58482 Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions — Network-AICWE-352 5.9 Medium2026-07-20
CVE-2026-46701 Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret — Network-AICWE-346 7.6 High2026-07-20
CVE-2026-58481 Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory — Network-AICWE-22 6.5 Medium2026-07-20
CVE-2026-58414 Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups — Network-AICWE-22 5.5 Medium2026-07-20
CVE-2026-58413 EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data — Network-AICWE-22 6.1 Medium2026-07-20
CVE-2026-54051 Network-AI has an an OS Command Injection issue — Network-AICWE-78 9.9 Critical2026-07-20
CVE-2026-64622 Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox — Network-AICWE-862 7.5 High2026-07-20
CVE-2026-64623 Network-AI before 5.13.4 Cryptographic Signature Verification Bypass — Network-AICWE-347 8.6 High2026-07-20
CVE-2026-48814 Network-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701) — Network-AICWE-306 9.1 Critical2026-06-17
CVE-2026-42856 Network-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool calls — Network-AICWE-306--2026-05-11

This page lists every published CVE security advisory associated with Jovancoding. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.