top of page
perceptive_background_267k.jpg

A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Messag…

Published:

5 August 2026 at 22:00:00

Alert date:

6 August 2026 at 09:03:45

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Emerging Technologies

A file inclusion vulnerability has been identified in TinyAGI version 0.0.20, specifically in the collectFiles function within packages/core/src/response.ts at the Message API Endpoint. The flaw allows remote attackers to exploit file inclusion through manipulation of the affected function. A public exploit is already available, increasing the risk of active attacks. The vulnerability was responsibly disclosed to the project maintainers via a GitHub issue, but no response or patch has been provided yet. The issue is tracked as CVE-2026-19009 and is listed on NVD and VulDB. The remote exploitability and public availability of the exploit make this a high-severity concern. Users of TinyAGI 0.0.20 are advised to monitor for patches or consider mitigations.

Technical details

Mitigation steps:

Affected products:

TinyAGI 0.0.20

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page