PT-2026-73197 · Unknown · Android-Mcp-Server

·

CVE-2026-19978

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions jiantao88 android-mcp-server versions prior to 14e2bf27c88ba137e35cbb0c2a75f72b595bb98a
Description An OS command injection flaw exists in the Command Execution component within the child process.exec() function of the build/index.js file. A local attacker can exploit this by manipulating the deviceId, packageName, permission, extras[].key, or extras[].value arguments. OS command injection is a vulnerability that allows an attacker to execute arbitrary operating system commands on the server.
Recommendations Apply patch 14e2bf27c88ba137e35cbb0c2a75f72b595bb98a to resolve the issue.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19978

Affected Products

Android-Mcp-Server