What is CVE-2026-19045?
CVE-2026-19045 is a command injection vulnerability found in the `SecretDialog.showSecretDialog` function of NocteDefensor LudusMCP up to version 1.0.24, specifically in the `get_credential_from_user` component. Manipulating the `Description` argument allows remote code execution, and users are advised to update to the latest patched version immediately.
Azərbaycanca: CVE-2026-19045 NocteDefensor LudusMCP proqramının 1.0.24-ə qədər versiyalarında `get_credential_from_user` komponentində `SecretDialog.showSecretDialog` funksiyasında aşkar edilmiş command injection zəifliyidir. Bu, `Description` arqumentinin manipulyasiyası ilə uzaqdan əmr icrasına imkan verir, təsirlənən sistemlərin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of NocteDefensor LudusMCP are affected by CVE-2026-19045?
This command injection vulnerability affects versions of LudusMCP up to 1.0.24.
How can one protect against CVE-2026-19045?
It is recommended to update to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.