What is CVE-2026-19039?
A command injection vulnerability was discovered in Kino-Kafkaesque ssh-mcp-server versions up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. The flaw exists in the `ssh_exec` function within `src/index.ts`, where manipulation of the `host` or `username` arguments can lead to remote code execution. Immediate update to the latest version is recommended.
Azərbaycanca: Kino-Kafkaesque ssh-mcp-server-in 8ebbbb99... versiyasına qədər olan versiyalarında `src/index.ts` faylındakı `ssh_exec` funksiyasında əmr inyeksiyası (command injection) zəifliyi aşkar edilib. Bu zəiflik `host` və ya `username` arqumentlərinin manipulyasiyası ilə uzaqdan kod icrasına səbəb ola bilər. İstifadəçilərə dərhal son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which software product is affected by CVE-2026-19039?
This vulnerability affects Kino-Kafkaesque ssh-mcp-server versions up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5.
How can remote code execution be achieved using CVE-2026-19039?
Remote code execution can be achieved by manipulating the `host` or `username` arguments in the `ssh_exec` function within `src/index.ts`, which leads to command injection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.