CVE-2026-19279 | MIMICLab mcp-pdf-vision 1.1.0 src/index.ts load_pdf pdfPath/sessionId command injection
A vulnerability was found in MIMICLab mcp-pdf-vision 1.1.0 and classified as critical. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection.
This vulnerability is referenced as CVE-2026-19279. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More