MCPA-2026-0068
lowrce-vectorsCVSS 5.3
mcp-pdf-vision page-extraction command injection (CVE-2026-19279)
mcp-pdf-vision (npm) 1.1.0: the load_pdf/extract_page path in src/index.ts interpolates the pdfPath and sessionId arguments into a pdftoppm shell command executed via child_process exec, allowing command injection through crafted paths or session ids (a double quote in pdfPath escapes the quoting). Version 1.0.0 does not contain the exec-based extraction. The project was informed through a public issue but has not responded and no fixed release exists, so the range is recorded as last_affected 1.1.0 per the public advisory.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | mcp-pdf-vision | >= 1.1.0, <= 1.1.0 |
Identifiers
CVE-2026-19279GHSA-jgc6-5vgc-hvqgCWE-74
References
- advisory https://github.com/advisories/GHSA-jgc6-5vgc-hvqg
- web https://nvd.nist.gov/vuln/detail/CVE-2026-19279
- web https://github.com/MIMICLab/mcp-pdf-vision
Timeline
- Published: 2026-08-08