CVE-2026-19266Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. This patch is called e0729dcfd3a2b1682a7bff86e7174852c03419ba. It is advisable to upgrade the affected component.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Patch / Workaround · 2026-08-08: 1Technical Details · 2026-08-08: 308-08
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-19266 A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component… https://www.cve.org/CVERecord?id=CVE-2026-19266

    Post summary

    The sentence announces CVE-2026-19266 as a discovered vulnerability in Kirachon context-engine, noting the affected function and file without providing any exploit or patch details.

    010001.1K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19266 A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component… https://www.cve.org/CVERecord?id=CVE-2026-19266 ----- Traducción: CVE-2026-19266 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑19266, identifying the vulnerable function in Kirachon context‑engine, but provides no exploitation evidence, PoC, or patch information.

    0000031
    98 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🔧 Context Engine MCP command injection patched CVE-2026-19266 affects Kirachon context-engine ≤1.9.0. The review-git-diff functionality can allow command injection through improperly handled Git arguments. ✅ Fixed in 1.9.1. 🔎 Source: Rapid7 / MITRE CVE #MCP #Git #DevSecOps #CVE #CyberSecurity

    Post summary

    The post reports that CVE‑2026‑19266, a command injection in Kirachon Context‑Engine up to 1.9.0, has been fixed in version 1.9.1, providing mitigation details.

    0000098
    34 followersView on X

Explore more