CVE-2026-19284

Source
https://cve.org/CVERecord?id=CVE-2026-19284
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19284.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19284
Published
2026-08-08T12:30:09.643Z
Modified
2026-08-09T03:46:06.302175863Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
MauricioMilano coder-api Projects Endpoint projects.ts createProject command injection
Details

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. The attack must be carried out locally. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-77"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19284.json"
}
References

Affected packages

Git / github.com/mauriciomilano/coder-api

Affected ranges

Type
GIT
Repo
https://github.com/mauriciomilano/coder-api
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.0"
        },
        {
            "last_affected": "1.0"
        },
        {
            "introduced": "1.1.0"
        },
        {
            "last_affected": "1.1.0"
        }
    ]
}

Affected versions

1.*
1.0
1.0.0
1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19284.json"