CVE-2026-19284General

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. The attack must be carried out locally. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 108-08
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    💻 Command-injection flaw disclosed in coder-api CVE-2026-19284 affects coder-api up to version 1.1.0. The vulnerability exists in its project-creation functionality and can result in command injection from a local attack context. 📅 Published: August 8 🔎 Source: CVE / VulDB vulnerability feed. #DevSecOps #CommandInjection #CVE #CyberSecurity

    Post summary

    The text announces CVE-2026-19284 as a command‑injection flaw in coder‑api, outlining the affected versions and vulnerability context, but it does not provide PoCs, exploitation tools, patches, or evidence of active attacks.

    0000037
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-19284 A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the com… https://www.cve.org/CVERecord?id=CVE-2026-19284 ----- Traducción: CVE-2026-19284 Se … http://infoflow.cloud`

    Post summary

    The text only references the CVE identifier and a link to the CVE record, with no additional technical details or actionable information.

    0000028
    98 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-19284 A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the com… https://www.cve.org/CVERecord?id=CVE-2026-19284

    Post summary

    The post merely references a CVE record for a vulnerability in MauricioMilano coder‑api, lacking details on exploitation, patches, or severity.

    00000819
    57.9K followersView on X

Explore more