CVE-2026-19263 | INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114 Servers Endpoint mcp-bridge.js command/args command injection
A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. It has been rated as critical. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of the argument command/args results in command injection.
This vulnerability is cataloged as CVE-2026-19263. It is possible to initiate the attack remotely. There is no exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More