CVE-2026-5831 Details
Description
A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading to version 2.1.9 will fix this issue. The patch is named c1550b445b9f24f38c4414e9a545f5f79f23a0fe. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A command injection vulnerability has been identified in Agions Taskflow-AI versions through 2.1.8. The issue resides in the MCP server handlers and executor components, specifically within the 'terminal_execute' tool, which is not publicly listed but can be invoked by attackers. The vulnerability allows for arbitrary OS command execution by exploiting insufficient input validation, potentially leading to full host compromise.
Users are advised to upgrade to Agions Taskflow-AI version 2.1.9 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 9, 2026CISA-ADP
Assessed Apr 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Agions/taskflow-ai/ | [email protected] | Source CodeVendor |
| https://github.com/Agions/taskflow-ai/commit/c1550b445b9f24f38c4414e9a545f5f79f23a0fe | [email protected] | Source CodeVendor |
| https://github.com/Agions/taskflow-ai/issues/2 | [email protected] | ExploitIssue TrackingRemedyTechnical DescriptionVendor |
| https://github.com/Agions/taskflow-ai/releases/tag/v2.1.9 | [email protected] | Release NotesVendor |
| https://vuldb.com/submit/789515 | [email protected] | Technical Description |
| https://vuldb.com/vuln/356278 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/356278/cti | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Agions taskflow-ai | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 9, 2026 | New CVE Received | [email protected] |
Volerion