Command Injection Vulnerability in Ask MCP Tool by Andrea Haku
CVE-2026-19329

4.8MEDIUM

Key Information:

Vendor

Andreahaku

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19329?

A command injection vulnerability has been identified in the Ask MCP Tool by Andrea Haku, specifically in the file src/codex-process-simple.ts. This issue arises from improper handling of user-provided input, allowing attackers to execute arbitrary commands within the application. Testing indicates that exploitation requires a local attack vector. Although the project team has been notified, there has been no response or patch released to address the vulnerability.

Affected Version(s)

codex_mcp 1ff521cc6cc57cfe56ddef946c644b8534771390

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu03 (VulDB User)
VulDB CNA Team
.