CVE-2026-19009 | TinyAGI 0.0.20 Message API Endpoint response.ts collectFiles file inclusion (Issue 282)
A vulnerability, which was classified as critical, has been found in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This manipulation causes file inclusion.
This vulnerability is handled as CVE-2026-19009. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More