What is CVE-2026-19282?
This vulnerability in earlier versions of `andreahaku llm_memory_mcp` allows command injection via the `hash` argument in the `auto.capture` function. It is recommended to update to the latest version to mitigate the risk.
Azərbaycanca: Bu boşluq `andreahaku llm_memory_mcp` proqramının əvvəlki versiyalarında `auto.capture` funksiyası vasitəsilə `hash` arqumentinə əmr yeridilməsinə (command injection) imkan verir. Təsirə məruz qalmamaq üçün proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: andreahaku
FAQ2
Through which function does CVE-2026-19282 allow command injection?
The vulnerability allows command injection via the `hash` argument in the `auto.capture` function.
What is recommended to mitigate CVE-2026-19282?
It is recommended to update to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.