CVE-2026-19263
Last modified
CVE-2026-19263 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of the argument command/args results in command injection. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The pull request to fix this issue awaits acceptance.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| INQUIRELAB | mcp-bridge-api | b30a82aa1d1d1139e0de846c41c8aadee6e06114 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19263?
How severe is CVE-2026-19263?
How do I fix CVE-2026-19263?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19246A vulnerability has been found in HKUDS nanobot up to 0.2.1.…6.3
- CVE-2026-19248QDomDocument XML parsing is vulnerable to a remotely-trigger…7.1
- CVE-2026-1925The EmailKit – Email Customizer for WooCommerce & WP plugin …4.3
- CVE-2026-19251The Ultimate Member WordPress plugin before 2.13.0 does not…5.3
- CVE-2026-19259A vulnerability has been found in MZ Automation libiec61850 …5.3
- CVE-2026-1926The Subscriptions for WooCommerce plugin for WordPress is vu…5.3
- CVE-2026-19264Postiz is an open-source social media scheduling tool. The r…9.8
- CVE-2026-19266A vulnerability was determined in Kirachon context-engine up…5.5
- CVE-2026-19267IBM Financial Transaction Manager (FTM) for RedHat OpenShift…6.2
- CVE-2026-19268A vulnerability was identified in abdullah1854 MCPGateway up…6.3
- CVE-2026-1927The Greenshift – animation and page builder blocks plugin fo…5.4
- CVE-2026-19270A security flaw has been discovered in Hulupeep mcp-ui-probe…5.3
Are you affected by CVE-2026-19263?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
