Command Injection Vulnerability in Tianxi AI Agent PC Application by Lenovo
CVE-2026-19136

8.4HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
10 September 2026

What is CVE-2026-19136?

A command injection vulnerability exists in the Tianxi AI Agent PC Application, which is specifically distributed in the Chinese market. This vulnerability could be exploited if a local user clicks on a specially crafted link that the application processes, potentially allowing unauthorized execution of operating system commands. It is crucial for users of this application to remain aware of this risk and take appropriate measures to secure their systems.

Affected Version(s)

Tianxi AI Agent PC Application 0 < 4.2.1.8111

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.