CVE detail
CVE-2026-19978
A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument deviceId/packageName/permission/extras[].key/extras[].value can lead to os command injection. It is possible to launch the attack on the local host. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This patch is called 14e2bf27c88ba137e35cbb0c2a75f72b595bb98a. It is advisable to implement a patch to correct this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 7
- within the 30d window
- Peak daily
- 7
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://vuldb.com/vuln/391157/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 4:16 AM - https://vuldb.com/vuln/391157vuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 4:16 AM - https://vuldb.com/submit/873898vuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 4:16 AM - https://vuldb.com/cve/CVE-2026-19978vuldb.com
No excerpt available.
Exploitvuldb.comAug 17, 2026, 4:16 AM No excerpt available.
Exploitgithub.comAug 17, 2026, 4:16 AM- https://github.com/jiantao88/android-mcp-server/commit/14e2bf27c88ba137e35cbb0c2a75f72b595bb98agithub.com
No excerpt available.
Exploitgithub.comAug 17, 2026, 4:16 AM No excerpt available.
Exploitgithub.comAug 17, 2026, 4:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19983CVSS 6.9 · Medium
A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_…
- CVE-2026-19982CVSS 5.3 · Medium
A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component Firewall-management RPC. The manipulation o…
- CVE-2026-19981CVSS 5.3 · Medium
A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000…
- CVE-2026-19771CVSS 7.3 · High
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manip…
- CVE-2026-72904CVSS 9.3 · Critical
Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functio…
- CVE-2026-72869CVSS 9.9 · Critical
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore bu…