Command Injection Vulnerability in slidev-builder-mcp by Adolfosalasgomez3011
CVE-2026-19281

4.8MEDIUM

Key Information:

Vendor
CVE Published:
8 August 2026

What is CVE-2026-19281?

A security flaw has been identified in the slidev-builder-mcp tool version 2.1.0, specifically involving a manipulation in the generateChart function within the generateAssets Tool. This vulnerability enables an attacker with local access to inject arbitrary commands by manipulating the outputDir argument. The issue was reported to the project maintainers, but there has been no official response or resolution as of yet.

Affected Version(s)

slidev-builder-mcp 2.1.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu02 (VulDB User)
VulDB CNA Team
.