What is CVE-2026-19041?
This vulnerability affects MissionSquad mcp-api up to version 1.11.8, allowing command injection via the NPM package installation function. Remote code execution may be possible on affected systems, so immediate patching is required.
Azərbaycanca: Bu zəiflik MissionSquad mcp-api məhsulunun 1.11.8-ə qədər versiyalarında NPM paket quraşdırma funksiyasında command injection-a yol açır. Təsirə məruz qalan sistemlərdə uzaqdan kod icrası mümkün ola bilər, dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which product is affected by CVE-2026-19041?
This vulnerability affects the MissionSquad mcp-api product up to version 1.11.8.
What kind of vulnerability is CVE-2026-19041?
CVE-2026-19041 is a command injection vulnerability in the NPM package installation function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.