Command Injection Vulnerability in Kirachon Context-Engine
CVE-2026-19266

5.1MEDIUM

Key Information:

Vendor

Kirachon

Vendor
CVE Published:
8 August 2026

What is CVE-2026-19266?

A command injection vulnerability has been identified in the Kirachon context-engine, affecting versions up to 1.9.0. This issue lies within the execGitCommand function in the gitUtils.ts file, specifically in the review-git-diff Endpoint. By manipulating the arguments passed to this function, an attacker could execute arbitrary commands on the server. Users are strongly advised to upgrade to version 1.9.1, where this vulnerability is addressed in patch e0729dcfd3a2b1682a7bff86e7174852c03419ba, in order to secure their applications.

Affected Version(s)

context-engine 1.0

context-engine 1.1

context-engine 1.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu02 (VulDB User)
.