PT-2026-31565 · Agions · Taskflow-Ai

Brucejin

·

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-5831

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Agions taskflow-ai versions through 2.1.8
Description A security flaw exists in Agions taskflow-ai up to version 2.1.8. The issue impacts an unknown function within the src/mcp/server/handlers.ts file of the terminal execute component, leading to OS command injection. The attack can be carried out remotely.
Recommendations Upgrade to version 2.1.9 to resolve this issue.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5831
GHSA-3XP3-PR8X-F755

Affected Products

Taskflow-Ai