CVE-2026-19263: INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection
A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of the argument command/args results in command injection. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19263?
The severity of CVE-2026-19263 is rated as high with a score of 7.3.
What type of vulnerability is CVE-2026-19263?
CVE-2026-19263 is a command injection vulnerability found in the INQUIRELAB mcp-bridge-api.
How do I fix CVE-2026-19263?
To fix CVE-2026-19263, ensure input validation is properly implemented to sanitize command/args arguments.
What impact does CVE-2026-19263 have?
CVE-2026-19263 allows for command injection, enabling an attacker to execute arbitrary commands on the server.
Which component is affected by CVE-2026-19263?
CVE-2026-19263 affects the Servers Endpoint functionality within the mcp-bridge.js file of the INQUIRELAB mcp-bridge-api.