CVE-2026-19041

Source
https://cve.org/CVERecord?id=CVE-2026-19041
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19041.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19041
Published
2026-08-06T13:30:13.459Z
Modified
2026-08-08T03:48:18.202720164Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection
Details

A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. Upgrading to version 1.11.9 is sufficient to resolve this issue. The identifier of the patch is a40f54d4533ba6618e1749383a245900eeb024c1. The affected component should be upgraded.

Database specific
{
    "cwe_ids": [
        "CWE-74",
        "CWE-77"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19041.json"
}
References

Affected packages

Git / github.com/missionsquad/mcp-api

Affected ranges

Type
GIT
Repo
https://github.com/missionsquad/mcp-api
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.11.0"
        },
        {
            "last_affected": "1.11.0"
        },
        {
            "introduced": "1.11.1"
        },
        {
            "last_affected": "1.11.1"
        },
        {
            "introduced": "1.11.2"
        },
        {
            "last_affected": "1.11.2"
        },
        {
            "introduced": "1.11.3"
        },
        {
            "last_affected": "1.11.3"
        },
        {
            "introduced": "1.11.4"
        },
        {
            "last_affected": "1.11.4"
        },
        {
            "introduced": "1.11.5"
        },
        {
            "last_affected": "1.11.5"
        },
        {
            "introduced": "1.11.6"
        },
        {
            "last_affected": "1.11.6"
        },
        {
            "introduced": "1.11.7"
        },
        {
            "last_affected": "1.11.7"
        },
        {
            "introduced": "1.11.8"
        },
        {
            "last_affected": "1.11.8"
        }
    ]
}

Affected versions

1.*
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.11.8
v1.*
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.11.6
v1.11.7
v1.11.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19041.json"