What is CVE-2026-19044?
A command injection vulnerability has been found in LeeSinLiang godot-mcp 0.1.0, affecting the "executeOperation" function in the "create_scene/add_node" component. This local flaw in "src/index.ts" could allow arbitrary command execution via the "projectPath" argument.
Azərbaycanca: LeeSinLiang godot-mcp 0.1.0 versiyasında "executeOperation" funksiyasında command injection zəifliyi aşkar edilib. Bu, "src/index.ts" faylındakı "create_scene/add_node" komponentinə təsir edir və lokal istismar nəticəsində ixtiyari əmrlərin icrasına səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which version of godot-mcp is affected by CVE-2026-19044?
This command injection vulnerability affects LeeSinLiang godot-mcp version 0.1.0.
Which component of godot-mcp contains the CVE-2026-19044 flaw?
The flaw exists in the "executeOperation" function of the "create_scene/add_node" component in the "src/index.ts" file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.