Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 08 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | MIMICLab mcp-pdf-vision index.ts load_pdf command injection | |
| First Time appeared |
Mimiclab
Mimiclab mcp-pdf-vision |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:mimiclab:mcp-pdf-vision:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mimiclab
Mimiclab mcp-pdf-vision |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-08T10:15:09.488Z
Reserved: 2026-08-07T15:31:41.649Z
Link: CVE-2026-19279
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-08T13:00:11Z