CVE-2026-19011: TinyAGI agents.ts buildSystemPrompt file inclusion
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19011?
The severity of CVE-2026-19011 is rated medium with a score of 5.3.
How can I fix CVE-2026-19011?
To fix CVE-2026-19011, update TinyAGI to a version that addresses the file inclusion vulnerability in the buildSystemPrompt function.
What type of vulnerability is CVE-2026-19011?
CVE-2026-19011 is a file inclusion vulnerability found in the TinyAGI application.
Can CVE-2026-19011 be exploited remotely?
Yes, CVE-2026-19011 can be exploited remotely, allowing attackers to manipulate the vulnerable function.
What elements are affected by CVE-2026-19011?
The affected element in CVE-2026-19011 is the function buildSystemPrompt located in the agents.ts file.