What is CVE-2026-19279?
A command injection vulnerability was found in the `load_pdf` function in `src/index.ts` of MIMICLab mcp-pdf-vision 1.1.0. Exploitation of `pdfPath` or `sessionId` arguments from a local environment allows arbitrary OS command execution. The project has been notified, and updating is advised.
Azərbaycanca: MIMICLab mcp-pdf-vision 1.1.0 versiyasında `src/index.ts` faylındakı `load_pdf` funksiyasında komanda inyeksiyası zəifliyi aşkar edilib. Bu, `pdfPath` və ya `sessionId` arqumenti vasitəsilə lokal mühitdən əməliyyat sistemi əmrlərinin icrasına imkan verir. Layihə məlumatlandırılıb, versiyanı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which function in MIMICLab mcp-pdf-vision 1.1.0 is vulnerable to command injection?
The command injection vulnerability was found in the `load_pdf` function in `src/index.ts`.
Through which arguments in a local environment can arbitrary OS commands be executed in CVE-2026-19279?
Arbitrary OS command execution is possible through the `pdfPath` or `sessionId` arguments from a local environment.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.