What is CVE-2026-19334?
A command injection vulnerability has been found in the NightTrek Ollama-mcp service, specifically in the 'src/index.ts' file. This flaw can be exploited locally through manipulation of the 'name', 'modelfile', 'source', or 'destination' arguments. Users are advised to update the product to the latest version.
Azərbaycanca: NightTrek Ollama-mcp servisində 'src/index.ts' faylında command injection zəifliyi aşkar edilib. Bu qüsur 'name', 'modelfile', 'source' və 'destination' arqumentlərinin manipulyasiyası nəticəsində yerli şəkildə istismar oluna bilər. İstifadəçilərə məhsulu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: NightTrek
FAQ2
In which file of the NightTrek Ollama-mcp service was the CVE-2026-19334 vulnerability found?
The vulnerability was found in the 'src/index.ts' file.
How can one protect against the CVE-2026-19334 vulnerability?
Users are advised to update the product to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.