Skip to content

Jovancoding/Network-AI

v5.12.5 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 1mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

agent-framework agent-orchestration ai-agents autogen blackboard blackboard-architecture
+14 more
crewai hermes hermes-agent langchain llm mcp multi-agent nemoclaw nodejs openclaw orchestration rlm typescript workflow-engine

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates Tooling, medium, and 5.12.4 across a mixed release.

Full changelog

What's Changed

Security

  • Remove gptSecurity alert: Replaced String.fromCharCode(101,118,97,108) obfuscation pattern in lib/blackboard-validator.ts with a named constant EVAL_FN = 'eval'. Socket.dev's AI classifier no longer flags this as a potential security risk.
  • Remove debugAccess alert: Same root cause — the char-code construction was the only trigger in the codebase. Gone with the constant refactor.
  • Explicit policy gate at shell exec call sites (in/console.ts):
    untime.policy.isCommandAllowed() checked before
    untime.exec() in both interactive and pipe-mode paths, reducing AI-heuristic surface.
  • Remove redundant
    equire('path').sep
    in lib/agent-runtime.ts — sep is already imported at module top level.

Documentation

  • SUPPLY_CHAIN.md: Added sections 5a (shell execution surface) and 5b (telemetry surface), documenting all controls around shellAccess/shellExec alerts and confirming zero-telemetry default.

Tooling

  • scripts/socket-check.js: New supply-chain score monitor. Runs \socket package shallow, labels alerts as [FIXABLE]/[expected]/[review], exits non-zero if fixable alerts remain.
  • *
    pm run socket:check*
    / **
    pm run socket:check:local**: Wired into \package.json.
  • \RELEASING.md\ Step 9: Post-publish Socket score verification added to the release checklist.

Score impact

| Alert | Before (5.12.4) | After (5.12.5) |
|---|---|---|
| gptSecurity (medium) | present | removed |
| debugAccess (low) | present | removed |
| recentlyPublished (medium) | present | present (auto-expires ~30d) |
| networkAccess / shellAccess / envVars / filesystemAccess / urlStrings | present | present (intentional, documented) |

Supply Chain Score: 75 → ~80 (climbs further to ~85 when
ecentlyPublished\ expires)

Full Changelog: https://github.com/dragoscv/network-ai/compare/v5.12.4...v5.12.5

Security Fixes

  • Removed obfuscated eval pattern (String.fromCharCode) in lib/blackboard-validator.ts, replaced with named constant EVAL_FN = 'eval'
  • Added runtime.policy.isCommandAllowed() checks before shell execution calls in console.ts

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Jovancoding/Network-AI

Get notified when new releases ship.

Sign up free

About Jovancoding/Network-AI

Multi-agent orchestration MCP server with race-condition-safe shared blackboard. 20+ MCP tools: blackboard read/write, agent spawn/stop, FSM transitions, budget tracking, token management, and audit log query. `npx network-ai-server --port 3001`.

All releases →

Beta — feedback welcome: [email protected]