What is CVE-2026-19964?
CVE-2026-19964 is a code injection vulnerability in Jij-Inc Jij-MCP-Server version 0.1.0, affecting the `PythonREPL.run` function in the `jij_mcp/python_repr.py` file of the `jm_check` component. It allows remote attackers to execute arbitrary code via argument manipulation, and users are advised to update immediately.
Azərbaycanca: CVE-2026-19964 Jij-Inc Jij-MCP-Server 0.1.0 versiyasında aşkarlanıb və `jm_check` komponentindəki `jij_mcp/python_repr.py` faylında yerləşən `PythonREPL.run` funksiyasında code injection zəifliyidir. Bu, uzaqdan hücumçuya arqument olaraq göndərilən kodu icra etməyə imkan verir, istifadəçilərə dərhal yeniləmə tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which version of Jij-MCP-Server is affected by CVE-2026-19964?
CVE-2026-19964 affects version 0.1.0 of Jij-Inc Jij-MCP-Server.
In which file and function of Jij-MCP-Server does this code injection vulnerability reside?
The vulnerability resides in the `PythonREPL.run` function within the `jij_mcp/python_repr.py` file of the `jm_check` component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.