Command Injection Vulnerability in MauricioMilano coder-api
CVE-2026-19284
4.8MEDIUM
What is CVE-2026-19284?
A security vulnerability has been found in the MauricioMilano coder-api affecting the createProject function within the Projects Endpoint's projects.ts file. This flaw allows an attacker with local access to manipulate commands, potentially executing unauthorized commands on the system. The vulnerability was reported via an issue ticket, but no actions have been taken by the vendor to address it, exposing users to potential risks.
Affected Version(s)
coder-api 1.0
coder-api 1.1.0
