What is CVE-2026-19978?
CVE-2026-19978 is a command execution vulnerability in jiantao88 android-mcp-server up to version cfb872b2446794193b58edd63f4dbf. The flaw stems from the child_process.exec function in build/index.js mishandling the deviceId, packageName, permission, and extras arguments. Immediate update or disabling of the affected component is recommended.
Azərbaycanca: CVE-2026-19978 jiantao88 android-mcp-server-in cfb872b2446794193b58edd63f4dbf versiyasına qədər təsir edən komanda icra zəifliyidir. Problem build/index.js faylında child_process.exec funksiyasının deviceId, packageName, permission, extras arqumentlərini təhlükəsiz işləməməsindən qaynaqlanır. Təcili olaraq serveri yeniləmək və ya təsirlənmiş komponenti söndürmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which product is affected by CVE-2026-19978 and where does the vulnerability lie?
This vulnerability affects the jiantao88 android-mcp-server up to version cfb872b2446794193b58edd63f4dbf. The flaw lies in the child_process.exec function within the build/index.js file mishandling its arguments.
What is the potential impact of exploiting CVE-2026-19978?
Since CVE-2026-19978 is a command execution vulnerability, successful exploitation could allow an attacker to run arbitrary commands on the server. Therefore, it is recommended to update the server or disable the affected component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.