CVE-2026-19281 | adolfosalasgomez3011 slidev-builder-mcp 2.1.0 generateAssets Tool generateAssets.ts generateChart outputDir command injection

SecurityVulns

A vulnerability was found in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. It has been classified as critical. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection.

This vulnerability is identified as CVE-2026-19281. The attack is only possible with local access. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More