CVE-2026-19010: TinyAGI Message API Endpoint index.ts processMessage authorization
A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19010?
CVE-2026-19010 has a severity rating of high at 7.3.
How do I fix CVE-2026-19010?
To fix CVE-2026-19010, ensure that proper authorization checks are implemented in the processMessage function of the TinyAGI Message API Endpoint.
What component is affected by CVE-2026-19010?
CVE-2026-19010 affects the Message API Endpoint in the TinyAGI software version 0.0.20.
Can CVE-2026-19010 be exploited remotely?
Yes, CVE-2026-19010 can be exploited remotely due to missing authorization in the processMessage function.
What could be the impact of exploiting CVE-2026-19010?
Exploiting CVE-2026-19010 could allow an attacker to manipulate the Message API Endpoint due to missing authorization.