Junglewise Threat Intelligence

CVE-2026-19281: adolfosalasgomez3011 slidev-builder-mcp command injection in generateChart

CVE-2026-19281 · Severity: medium · CVSS 5.3 · Published 2026-08-08

Executive brief

slidev-builder-mcp is a tool that builds presentation slideshows using an AI model server architecture. A command injection vulnerability in the chart generation function allows a local attacker to execute arbitrary system commands by manipulating the output directory parameter, potentially compromising the machine running the presentation builder.

Technical details

The vulnerability is a shell command injection in the generateChart function within src/tools/generateAssets.ts. The vulnerable code constructs a shell command string by directly interpolating a caller-controlled outputDir parameter into the Python script path without proper escaping: `execAsync(\`python "${scriptPath}"\`)` where scriptPath is derived from the untrusted outputDir. An attacker can inject shell metacharacters (such as backticks, quotes, or semicolons) through a crafted directory name to break out of the quoted path and execute arbitrary commands. The attack requires local access and the ability to invoke the generateAssets tool with assetType set to "chart". The fix is to use spawn/execFile with an explicit argument array instead of constructing shell strings, and optionally restrict outputDir to an approved workspace root.

Affected products

  • adolfosalasgomez3011 slidev-builder-mcp 2.1.0

Timeline

  • 2026-04-29: disclosed: Vulnerability reported via GitHub issue
  • 2026-08-08: advisory: CVE-2026-19281 published on NVD

References