Command Injection Vulnerability in MCPGateway by Abdullah1854
CVE-2026-19268
Key Information:
- Vendor
Abdullah1854
- Status
- Vendor
- CVE Published:
- 8 August 2026
Badges
What is CVE-2026-19268?
A command injection vulnerability has been identified in the MCPGateway by Abdullah1854, specifically within the 'getUsageByDateRange' function located in the file 'src/services/claude-usage.ts'. This vulnerability arises due to improper handling of input parameters, allowing an attacker to manipulate the 'since' argument and execute arbitrary commands on the server. The vulnerability is accessible remotely, which significantly increases its potential for exploitation. Although the project maintainers were earlier informed of this security issue, no response or resolution has been provided as of now. This is a serious concern for users relying on the continuous delivery model of this product, as affected version details are unavailable.
Affected Version(s)
MCPGateway 549f494a9e363f40530149de324b8097de424230
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
