v5.15.2 - security fixes
GHSA-9p2w-prp8-5722 (High) - ClaudeHookBridge deny patterns now inspect every string field of toolinput (e.g. Write.content, Edit.newstring, MCP tool arguments), not just the first candidate field. Over-nested or oversiz
Security fixes
- GHSA-9p2w-prp8-5722 (High) -
ClaudeHookBridgedeny patterns now inspect every string field oftool_input(e.g.Write.content,Edit.new_string, MCP tool arguments), not just the first candidate field. Over-nested or oversized inputs fail closed. Reported by zx (Jace) / @manus-use. - GHSA-hr6v-mfxm-4438 (Moderate) -
DashboardServernow validates theHostheader (blocks DNS rebinding) and the WebSocketOrigin(blocks cross-site WebSocket hijacking). NewallowedHosts/allowedOriginsoptions for proxied deployments. Reported by zx (Jace) / @manus-use. - GHSA-4pvg-m42h-c3x2 (Low) -
McpSseServerreflects a localhost CORSOriginonly when bound to a loopback address. Reported via Sebastion AI (@andesyteoss). - CodeQL #180 (
js/regex-injection) - hook deny/allow regexes are validated at construction (invalid, oversized, or nested-quantifier patterns rejected);network-ai hook pre-tool-useexits2on any error so a bad rule blocks instead of silently allowing. - CodeQL #179 (
js/incomplete-sanitization) -scripts/clawhub-publish.jsrejects arguments cmd.exe cannot safely quote and no longer uses a shell on non-Windows platforms.
Behaviour changes
- Deny patterns now also see file contents and tool arguments, so a rule like
--deny "rm -rf"will block writing a file that containsrm -rf. - A
DashboardServerbehind a reverse proxy with a different hostname must setallowedHosts/allowedOrigins.
CI / maintenance
- OpenSSF Scorecard:
ossf/scorecard-actionv2.4.4 (image moved from gcr.io to ghcr.io). - Examples load
dotenvvia its typed main entry (dotenv 18 compatibility).
3,673 tests across 41 suites.
Full changelog: https://github.com/Jovancoding/Network-AI/blob/main/CHANGELOG.md