Tinyagi · Tinyagi · CVE-2026-19009
**Name of the Vulnerable Software and Affected Versions**
TinyAGI version 0.0.20
**Description**
A remote file inclusion issue exists within the Message API Endpoint component. The flaw is located in the `collectFiles()` function within the `packages/core/src/response.ts` file, allowing an attacker to remotely include files.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the `collectFiles()` function to minimize the risk of exploitation.