Command Injection Vulnerability in MIMICLab mcp-pdf-vision Product
CVE-2026-19279

4.8MEDIUM

Key Information:

Vendor

Mimiclab

Vendor
CVE Published:
8 August 2026

What is CVE-2026-19279?

MIMICLab's mcp-pdf-vision version 1.1.0 contains a command injection vulnerability in the load_pdf function implemented in src/index.ts. The flaw allows an attacker to manipulate the pdfPath or sessionId arguments, enabling malicious command execution within a local environment. Despite the early reporting of this issue through an official issue track, there has been no response from the MIMICLab project team, increasing the risk for users relying on this software in their systems.

Affected Version(s)

mcp-pdf-vision 1.1.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu02 (VulDB User)
VulDB CNA Team
.