CVE-2026-19978 | jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292 Command Execution build/index.js child_process.exec os command injection
A vulnerability labeled as problematic has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument deviceId/packageName/permission/extras[].key/extras[].value can lead to os command injection.
This vulnerability is handled as CVE-2026-19978. It is possible to launch the attack on the local host. Additionally, an exploit exists.
This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More