Command Injection Vulnerability in MauricioMilano coder-api
CVE-2026-19284

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 August 2026

What is CVE-2026-19284?

A security vulnerability has been found in the MauricioMilano coder-api affecting the createProject function within the Projects Endpoint's projects.ts file. This flaw allows an attacker with local access to manipulate commands, potentially executing unauthorized commands on the system. The vulnerability was reported via an issue ticket, but no actions have been taken by the vendor to address it, exposing users to potential risks.

Affected Version(s)

coder-api 1.0

coder-api 1.1.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu02 (VulDB User)
VulDB CNA Team
.