Junglewise Threat Intelligence

CVE-2026-19136: Tianxi AI Agent PC Application command injection

CVE-2026-19136 · Severity: high · CVSS 7.8 · Published 2026-09-10

Vendors: Lenovo.

Executive brief

Tianxi AI Agent is a PC application distributed in China that handles custom links opened by users. A vulnerability allows attackers to execute arbitrary operating system commands when a user opens a specially crafted link, potentially compromising the user's system and data.

Technical details

A command injection vulnerability exists in the Tianxi AI Agent PC Application's link handling mechanism. The application fails to properly sanitize or validate URL parameters before passing them to system command execution functions. An attacker can craft a malicious link that, when opened by a local user, causes the application to execute arbitrary operating system commands with the privileges of the user running the application. This is a local attack vector requiring user interaction (opening the malicious link). No patch information is currently available based on the advisory.

Affected products

  • Lenovo Tianxi AI Agent PC Application

Timeline

  • 2026-09-10: disclosed

References