MEDIUM
Agions
CVE published 2026-04-09
CVE-2026-5831
A security flaw has been discovered in Agions taskflow-ai up to 2.1.8, impacting the terminal_execute component in the src/mcp/server/handlers.ts file. This vulnerability results in os command injection, allowing remote exploitation. Upgrading to version 2.1.9 will fix this issue. The patch is named c1550b445b9f24f38c4414e9a545f5f79f23a0fe. The vendor responded professionally and quickly released a fixed version.