CVE-2026-19266 | Kirachon context-engine up to 1.9.0 review-git-diff Endpoint gitUtils.ts execGitCommand args command injection (Issue 16)

SecurityVulns

A vulnerability categorized as critical has been discovered in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection.

This vulnerability is registered as CVE-2026-19266. The attack requires access to the local network. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More