Unknown · Android-Mcp-Server · CVE-2026-19978
**Name of the Vulnerable Software and Affected Versions**
jiantao88 android-mcp-server versions prior to 14e2bf27c88ba137e35cbb0c2a75f72b595bb98a
**Description**
An OS command injection flaw exists in the Command Execution component within the `child process.exec()` function of the `build/index.js` file. A local attacker can exploit this by manipulating the `deviceId`, `packageName`, `permission`, `extras[].key`, or `extras[].value` arguments. OS command injection is a vulnerability that allows an attacker to execute arbitrary operating system commands on the server.
**Recommendations**
Apply patch 14e2bf27c88ba137e35cbb0c2a75f72b595bb98a to resolve the issue.