PT-2026-69189 · Abdullah1854 · Mcp-Gateway

·

CVE-2026-19268

·

Published

2026-08-08

·

Updated

2026-08-08

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions abdullah1854 MCPGateway versions up to 549f494a9e363f40530149de324b8097de424230
Description Remote command injection is possible within the Claude Usage Range Endpoint component. The issue exists in the getUsageByDateRange() function located in the src/services/claude-usage.ts file, where improper handling of the since argument allows an attacker to execute arbitrary commands on the system.
Recommendations As a temporary workaround, restrict access to the getUsageByDateRange() function until a fix is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19268

Affected Products

Mcp-Gateway