CVE-2026-19136: OS Command Injection
A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tianxi AI Agent PC Applicationto a version that resolves this vulnerability.Fixed in 4.2.1.8111
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems with the Tianxi AI Agent PC Application are exposed when a local user opens a specially crafted link that the application handles. The application is distributed exclusively in the Chinese market.
What does exploitation require?
Exploitation requires user interaction: a local user must open a specially crafted link handled by the application. The vulnerability has local attack vector characteristics and does not require privileges.
What could a successful exploit allow?
A successful exploit could execute operating system commands. The reported severity vector indicates potential high impact to confidentiality, integrity, and availability.