Command Injection Vulnerability in INQUIRELAB mcp-bridge-api
CVE-2026-19263
6.9MEDIUM
What is CVE-2026-19263?
A vulnerability exists in the INQUIRELAB mcp-bridge-api, specifically in the 'Servers Endpoint' within the mcp-bridge.js file. By manipulating the command/args argument, an attacker can execute arbitrary commands remotely. The product employs a rolling release model, resulting in the absence of specific version numbers for both the affected and updated releases. A pull request aimed at mitigating this issue is currently pending acceptance.
Affected Version(s)
mcp-bridge-api b30a82aa1d1d1139e0de846c41c8aadee6e06114
