CVE-2026-19136

Summary

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.

Affected Software

VendorProductVersion RangeStatus
LenovoTianxi AI Agent PC Application0 < 4.2.1.8111affected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References