A vulnerability was found in Jovancoding Network-AI up to 5.4.4. It has been declared as critical. Affected by this vulnerability is the function
_isAuthorized of the file lib/mcp-transport-sse.ts of the component MCP SSE Server. Such manipulation of the argument NETWORK_AI_MCP_SECRET leads to improper authorization.
This vulnerability is documented as CVE-2026-46701. The attack can be executed remotely. There is not any exploit available.