Command Injection Vulnerability in INQUIRELAB mcp-bridge-api
CVE-2026-19263

6.9MEDIUM

Key Information:

Vendor

Inquirelab

Vendor
CVE Published:
8 August 2026

What is CVE-2026-19263?

A vulnerability exists in the INQUIRELAB mcp-bridge-api, specifically in the 'Servers Endpoint' within the mcp-bridge.js file. By manipulating the command/args argument, an attacker can execute arbitrary commands remotely. The product employs a rolling release model, resulting in the absence of specific version numbers for both the affected and updated releases. A pull request aimed at mitigating this issue is currently pending acceptance.

Affected Version(s)

mcp-bridge-api b30a82aa1d1d1139e0de846c41c8aadee6e06114

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu02 (VulDB User)
VulDB CNA Team
.