Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-19039: Command injection in Kino-Kafkaesque ssh-mcp-server

A command injection vulnerability was detected in the SSH Command Handler component of Kino-Kafkaesque ssh-mcp-server through commit 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. The vulnerability allows manipulation of host/username arguments to achieve command injection, though the project maintainer disputes the threat given the tool's intended use model as a local trusted agent.

Disclosed 6 August 2026 · Record updated 13 September 2026

Impact

Command injection vulnerability in SSH command execution handler; threat model disputed by maintainer as tool is designed for local trusted use only.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-19039