What is CVE-2026-19958?
CVE-2026-19958 is a critical security flaw discovered in iatsiuk pptr-mcp up to version 0.2.7. The vulnerability exists in the 'executeCode' function within the 'src/vm-executor.ts' file of the 'execute' tool, allowing remote code injection attacks. Users should immediately update to the latest version.
Azərbaycanca: CVE-2026-19958 iatsiuk pptr-mcp-in 0.2.7 versiyasına qədər olan versiyalarında aşkarlanmış kritik bir təhlükəsizlik qüsurudur. Bu zəiflik 'execute' alətinin 'src/vm-executor.ts' faylındakı 'executeCode' funksiyasında code injection hücumuna imkan verir. İstifadəçilər dərhal ən son versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
In which component of pptr-mcp does the CVE-2026-19958 vulnerability exist?
The vulnerability exists in the 'executeCode' function within the 'src/vm-executor.ts' file of the 'execute' tool.
What security risk does CVE-2026-19958 pose?
This flaw is a critical security vulnerability that allows code injection attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.