Vulnerability  ·  2026-08-08

MissionSquad mcp-api — Command Injection via NPM Package Version Handler

VulnerabilityMedium impactGlobalCVE-2026-19041
NVD published CVE-2026-19041 (CVSS 6.3, Medium) on August 6, 2026, describing an OS command injection vulnerability in MissionSquad's mcp-api package installation controller.
An MCP-API server that installs npm packages on behalf of an agent is a high-value target — command injection here gives a remote attacker code execution on the MCP host, potentially compromising every agent connected to that server.
The packageService.installPackage function in the NPM Package Version Handler fails to sanitize input, allowing an attacker to inject and execute arbitrary OS commands remotely via crafted package/version parameters.
MissionSquad mcp-api ≤ 1.11.8
Upgrade to a patched mcp-api release.
NVD CVE-2026-19041MissionSquad/mcp-api GitHub
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →