What is CVE-2026-19263?
A command injection vulnerability has been identified in INQUIRELAB mcp-bridge-api. The flaw resides in the Servers Endpoint component within `mcp-bridge.js`, allowing arbitrary command execution via manipulation of the `command` or `args` arguments. Organizations using affected versions should immediately apply the vendor-supplied patch.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
In which file does the critical command injection vulnerability in INQUIRELAB mcp-bridge-api reside?
The vulnerability resides in the Servers Endpoint component within the `mcp-bridge.js` file.
CVE-2026-19263 zəifliyi hansı arqumentlərin manipulyasiyası ilə ixtiyari əmrlərin icrasına imkan yaradır?
`command` və ya `args` arqumentlərinin manipulyasiyası ilə.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.