Sceawere

Vulnerability Detail

CVE-2026-19978UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

jiantao88 android-mcp-server OS Command Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
jiantao88
Product
android-mcp-server
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument deviceId/packageName/permission/extras[].key/extras[].value can lead to os command injection. It is possible to launch the attack on the local host. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This patch is called 14e2bf27c88ba137e35cbb0c2a75f72b595bb98a. It is advisable to implement a patch to correct this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-17T04:16:54.783Z",
  "pubdate": "2026-08-17T04:16:54.783Z",
  "executiveSummary": "A critical OS command injection vulnerability has been identified in the jiantao88 android-mcp-server component up to commit cfb872b2446794193b58edd63f4dbf6af48a6292. The vulnerability arises from unsafe handling of input parameters within the command execution functionality, allowing local attackers to execute arbitrary operating system commands with the privileges of the running application. The flaw affects the build/index.js file where user-supplied input is directly passed to underlying shell execution sinks. Successful exploitation can lead to full system compromise of the local host. Given that public exploit material is available, the risk to vulnerable deployments is considered high. Remediation requires applying the official patch referenced as 14e2bf27c88ba137e35cbb0c2a75f72b595bb98a.",
  "technicalDetails": "The vulnerability is an OS command injection flaw located in the build/index.js file of the jiantao88 android-mcp-server component. The root cause stems from the insecure usage of the child_process.exec function, which spawns a shell to execute commands passed as strings. Specifically, input parameters including deviceId, packageName, permission, extras[].key, and extras[].value are improperly sanitized or concatenated directly into command strings without adequate validation or escaping. Attackers capable of interacting with the local host can manipulate these input parameters by injecting malicious shell metacharacters, command separators, or arbitrary command sequences. When the application processes the crafted payload, the underlying shell interprets the injected sequences and executes the attacker-supplied commands in addition to or instead of the intended operation. This vulnerability requires local access to the host environment, bypassing intended functional restrictions and leading to arbitrary OS command execution within the security context of the Node.js process. The affected software utilizes a rolling release model, impacting all versions up to commit cfb872b2446794193b58edd63f4dbf6af48a6292."
}
CVE-2026-19978: jiantao88 android-mcp-server OS Command Injection (MEDIUM Severity, CVSS: 5.3) - Sceawere