CVE-2026-19136
Deferred Deferred - Pending Action

Command Injection in Tianxi AI Agent PC Application

Vulnerability report for CVE-2026-19136, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Lenovo Group Ltd.

Description

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lenovo tianxi_ai_agent_pc_application *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a command injection vulnerability in the Tianxi AI Agent PC Application. It allows an attacker to execute operating system commands on a victim's machine if they open a specially crafted link that the application processes. The vulnerability exists because the application does not properly validate or sanitize input from links it handles.

Detection Guidance

Since this is a command injection vulnerability in the Tianxi AI Agent PC Application, detection would involve checking for unusual command execution or network activity from the application. Monitor processes running under the application's name and inspect network traffic for unexpected connections. No specific commands are provided in the CVE details.

Impact Analysis

If you use the Tianxi AI Agent PC Application, an attacker could trick you into opening a malicious link. This could lead to unauthorized execution of commands on your system, potentially allowing the attacker to take control of your computer, steal data, or install malware. The impact depends on the permissions of the application and your system.

Compliance Impact

This vulnerability could lead to data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. If exploited, it could result in unauthorized access to personal or sensitive data, triggering legal and financial penalties for organizations failing to protect such data.

Mitigation Strategies

Immediately uninstall or disable the Tianxi AI Agent PC Application if present. Ensure no untrusted links are opened with the application. Apply any available patches or updates from the vendor. Monitor system logs for suspicious activity related to command execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19136. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart