CVE-2026-19266
Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. This patch is called e0729dcfd3a2b1682a7bff86e7174852c03419ba. It is advisable to upgrade the affected component.
| CWE | CWE-77 CWE-74 |
| Vendor | kirachon |
| Product | context-engine |
| Published | Aug 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for kirachon context-engine
Be the first to know when new medium vulnerabilities affecting kirachon context-engine are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Kirachon / context-engine
1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.8 1.9.0
References
vuldb.com: https://vuldb.com/vuln/387011 vuldb.com: https://vuldb.com/vuln/387011/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19266 vuldb.com: https://vuldb.com/submit/865221 github.com: https://github.com/Kirachon/context-engine/issues/16 github.com: https://github.com/Kirachon/context-engine/issues/16#issuecomment-4321217057 github.com: https://github.com/Kirachon/context-engine/commit/e0729dcfd3a2b1682a7bff86e7174852c03419ba github.com: https://github.com/Kirachon/context-engine/releases/tag/v1.9.1 github.com: https://github.com/Kirachon/context-engine/
Credits
๐ gongyanyu02 (VulDB User)