CVE-2026-19282: A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of th...

Added to the CISA Known Exploited Vulnerabilities catalog on 08 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 5.3.

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead to command inject...

Required action: Review and patch if applicable to your AI infrastructure.