๐Ÿ” CVE Alert

CVE-2026-19266

MEDIUM 5.5

Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. This patch is called e0729dcfd3a2b1682a7bff86e7174852c03419ba. It is advisable to upgrade the affected component.

CWE CWE-77 CWE-74
Vendor kirachon
Product context-engine
Published Aug 8, 2026
Stay Ahead of the Next One

Get instant alerts for kirachon context-engine

Be the first to know when new medium vulnerabilities affecting kirachon context-engine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Kirachon / context-engine
1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.8 1.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387011 vuldb.com: https://vuldb.com/vuln/387011/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19266 vuldb.com: https://vuldb.com/submit/865221 github.com: https://github.com/Kirachon/context-engine/issues/16 github.com: https://github.com/Kirachon/context-engine/issues/16#issuecomment-4321217057 github.com: https://github.com/Kirachon/context-engine/commit/e0729dcfd3a2b1682a7bff86e7174852c03419ba github.com: https://github.com/Kirachon/context-engine/releases/tag/v1.9.1 github.com: https://github.com/Kirachon/context-engine/

Credits

๐Ÿ” gongyanyu02 (VulDB User)