CVE-2026-19266: Command Injection in Kirachon context-engine
A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. This patch is called e0729dcfd3a2b1682a7bff86e7174852c03419ba. It is advisable to upgrade the affected component.
AI Analysis
Technical Summary
This vulnerability exists in the Kirachon context-engine component review-git-diff endpoint, specifically in the execGitCommand function of src/mcp/utils/gitUtils.ts. Improper handling of the 'args' parameter allows an attacker with local privileges to inject arbitrary commands. The issue is fixed in version 1.9.1 by patch e0729dcfd3a2b1682a7bff86e7174852c03419ba. The CVSS 4.0 base score is 5.1, indicating a medium severity vulnerability with local attack vector and low privileges required.
Potential Impact
An attacker with local access and low privileges can manipulate the argument passed to execGitCommand, leading to command injection. This could allow execution of arbitrary commands with the privileges of the vulnerable process, potentially compromising system integrity or confidentiality. However, the attack requires local access and low privileges, limiting the scope of exploitation.
Mitigation Recommendations
Upgrade Kirachon context-engine to version 1.9.1 or later, which contains the patch e0729dcfd3a2b1682a7bff86e7174852c03419ba that fixes the command injection vulnerability. No other mitigation or temporary workaround is indicated.
CVE-2026-19266: Command Injection in Kirachon context-engine
Description
A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. This patch is called e0729dcfd3a2b1682a7bff86e7174852c03419ba. It is advisable to upgrade the affected component.
CVSS v4.0
Score 5.1medium
Affected software
Kirachon
context-engine
pkg:github/kirachon/context-enginecpe:2.3:a:kirachon:context-engine:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the Kirachon context-engine component review-git-diff endpoint, specifically in the execGitCommand function of src/mcp/utils/gitUtils.ts. Improper handling of the 'args' parameter allows an attacker with local privileges to inject arbitrary commands. The issue is fixed in version 1.9.1 by patch e0729dcfd3a2b1682a7bff86e7174852c03419ba. The CVSS 4.0 base score is 5.1, indicating a medium severity vulnerability with local attack vector and low privileges required.
Potential Impact
An attacker with local access and low privileges can manipulate the argument passed to execGitCommand, leading to command injection. This could allow execution of arbitrary commands with the privileges of the vulnerable process, potentially compromising system integrity or confidentiality. However, the attack requires local access and low privileges, limiting the scope of exploitation.
Mitigation Recommendations
Upgrade Kirachon context-engine to version 1.9.1 or later, which contains the patch e0729dcfd3a2b1682a7bff86e7174852c03419ba that fixes the command injection vulnerability. No other mitigation or temporary workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-07T14:10:48.765Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a76ddc6bf8831d539252daa
Added to database: 08/08/2026, 07:41:58 UTC
Last enriched: 08/15/2026, 14:43:27 UTC
Last updated: 09/22/2026, 01:54:35 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.