CVE-2026-19041 | MissionSquad mcp-api up to 1.11.8 NPM Package Version packages.ts this.packageService.installPackage command injection

SecurityVulns

A vulnerability has been found in MissionSquad mcp-api up to 1.11.8 and classified as critical. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection.

This vulnerability is traded as CVE-2026-19041. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More