CVE-2026-19268 | abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230 Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange since command injection
A vulnerability identified as critical has been detected in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint. The manipulation of the argument since leads to command injection.
This vulnerability is documented as CVE-2026-19268. The attack can be initiated remotely. Additionally, an exploit exists.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More