CVE-2026-19136 PUBLISHED

Assigner: lenovo
Reserved: 06.08.2026 Published: 10.09.2026 Updated: 10.09.2026

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor Lenovo
Product Tianxi AI Agent PC Application
Versions Default: unaffected
  • affected from 0 to 4.2.1.8111 (excl.)

Solutions

Update Tianxi AI Agent PC Application version to 4.2.1.8111 or later.

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE