What is CVE-2026-19268?
This vulnerability exists in the abdullah1854 MCPGateway tool, specifically in the `getUsageByDateRange` function within the `src/services/claude-usage.ts` file. Manipulating the `since` argument leads to command injection. Affected systems are at risk of remote code execution, requiring immediate patching or restricted access to the Claude Usage Range Endpoint.
Azərbaycanca: Bu boşluq abdullah1854 MCPGateway proqramında `src/services/claude-usage.ts` faylındakı `getUsageByDateRange` funksiyasında aşkarlanıb. `since` arqumenti üzərində manipulyasiya command injection zəifliyinə səbəb olur. Bu, təsirlənən sistemlərdə uzaqdan kod icrası riski yaradır, dərhal yamaq tətbiq edilməli və ya həmin endpointe giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which function is exploited in CVE-2026-19268?
The vulnerability is exploited through manipulation of the `since` argument in the `getUsageByDateRange` function within `src/services/claude-usage.ts`.
What risk does exploiting CVE-2026-19268 pose?
This command injection vulnerability poses a risk of remote code execution (RCE) on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.