CVE detail
CVE-2026-19011
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. The attack may be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 6
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://vuldb.com/vuln/386404/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 8:16 AM - https://vuldb.com/vuln/386404vuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 8:16 AM - https://vuldb.com/submit/862674vuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 8:16 AM - https://vuldb.com/cve/CVE-2026-19011vuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 8:16 AM No excerpt available.
Exploitgithub.comAug 6, 2026, 8:16 AM- https://github.com/TinyAGI/tinyagi/github.com
No excerpt available.
Exploitgithub.comAug 6, 2026, 8:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19353CVSS 1.3 · Low
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard.…
- CVE-2026-54200CVSS 8.4 · High
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' comma…
- CVE-2026-12070CVSS 8.4 · High
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFI…
- CVE-2026-19009CVSS 5.5 · Medium
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. Thi…
- CVE-2026-16054CVSS 9.1 · Critical
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control g…
- CVE-2026-60009CVSS 8.8 · High
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attack…