What is CVE-2026-19281?
This critical vulnerability is a command injection flaw in the `generateChart` function of the `generateAssets` tool in adolfosalasgomez3011 slidev-builder-mcp 2.1.0, caused by improper handling of the `outputDir` argument. It allows attackers to execute arbitrary commands on the server, and immediate update is recommended.
Azərbaycanca: Bu kritik zəiflik adolfosalasgomez3011 slidev-builder-mcp 2.1.0 versiyasında `generateAssets` alətinin `generateChart` funksiyasındakı `outputDir` arqumentinin düzgün yoxlanılmaması səbəbindən command injection hücumlarına imkan verir. Bu, təcavüzkara serverdə ixtiyari əmrlər icra etməyə şərait yaradır, dərhal proqramı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ1
Which component does CVE-2026-19281 affect and how is it exploited?
This vulnerability is a command injection flaw in the `generateChart` function of the `generateAssets` tool in adolfosalasgomez3011 slidev-builder-mcp 2.1.0, caused by improper handling of the `outputDir` argument. It allows attackers to execute arbitrary commands on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.