CVE-2026-19281: adolfosalasgomez3011 slidev-builder-mcp generateAssets Tool generateAssets.ts generateChart command injection
A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with local access. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19281?
The severity of CVE-2026-19281 is rated as medium with a score of 5.3.
What type of vulnerability is CVE-2026-19281?
CVE-2026-19281 is classified as a Command Injection vulnerability.
How do I fix CVE-2026-19281?
To fix CVE-2026-19281, ensure proper input validation to prevent command injection in the generateChart function.
Which component is affected by CVE-2026-19281?
CVE-2026-19281 affects the generateAssets Tool in the adolfosalasgomez3011 slidev-builder-mcp version 2.1.0.
What are the potential impacts of CVE-2026-19281?
Exploitation of CVE-2026-19281 could lead to unauthorized command execution on the host system.