CVE-2026-19039: Command injection in Kino-Kafkaesque ssh-mcp-server
A command injection vulnerability was detected in the SSH Command Handler component of Kino-Kafkaesque ssh-mcp-server through commit 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. The vulnerability allows manipulation of host/username arguments to achieve command injection, though the project maintainer disputes the threat given the tool's intended use model as a local trusted agent.
Disclosed 6 August 2026 · Record updated 13 September 2026
Impact
Command injection vulnerability in SSH command execution handler; threat model disputed by maintainer as tool is designed for local trusted use only.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19039
