CVE-2026-19282: andreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injection
A weakness has been identified in andreahaku llmmemorymcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llmmemorymcp. Executing a manipulation of the argument hash can lead to command injection. The attack is restricted to local execution. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19282?
The severity of CVE-2026-19282 is medium with a score of 5.3.
What type of vulnerability is associated with CVE-2026-19282?
CVE-2026-19282 is a command injection vulnerability.
How do I fix CVE-2026-19282?
To fix CVE-2026-19282, ensure that input validation is implemented for the argument hash in the auto.capture function.
What impact does CVE-2026-19282 have on the software?
CVE-2026-19282 can lead to command injection vulnerabilities in the llm_memory_mcp software.
Which software is affected by CVE-2026-19282?
CVE-2026-19282 affects the andreahaku/llm_memory_mcp software, specifically versions up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0.