mediumCVSS 6.3Vulnerability

CVE-2026-5831

A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading to version 2.1.9 will fix this issue. The patch is named c1550b445b9f24f38c4414e9a545f5f79f23a0fe. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Properties

severity
medium
summary
Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts
epss_score
0.0111
cvss_score
6.3
ghsa_published
2026-04-09T03:31:14Z
source_url
https://github.com/advisories/GHSA-3xp3-pr8x-f755
ghsa_updated
2026-04-10T19:19:47Z
ghsa_id
GHSA-3xp3-pr8x-f755
cve_id
CVE-2026-5831
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.62948

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/taskflow-ai

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/taskflow-ai

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5831 (CVSS 6.3) — Ninja Signal Threat Intelligence | Ninja Signal