


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Messag…
Published:
6 August 2026 at 00:00:00
Alert date:
6 August 2026 at 11:03:45
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies
A file inclusion vulnerability has been identified in TinyAGI version 0.0.20, specifically in the collectFiles function within packages/core/src/response.ts at the Message API Endpoint. The flaw allows remote attackers to exploit file inclusion through manipulation of the affected function. A public exploit is already available, increasing the risk of active attacks. The vulnerability was responsibly disclosed to the project maintainers via a GitHub issue, but no response or patch has been provided yet. The issue is tracked as CVE-2026-19009 and is listed on NVD and VulDB. The remote exploitability and public availability of the exploit make this a high-severity concern. Users of TinyAGI 0.0.20 are advised to monitor for patches or consider mitigations.
Technical details
Mitigation steps:
Affected products:
TinyAGI 0.0.20
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-19009
https://github.com/TinyAGI/tinyagi/
https://github.com/TinyAGI/tinyagi/issues/282
https://vuldb.com/cve/CVE-2026-19009
https://vuldb.com/submit/862672
https://vuldb.com/vuln/386402
https://vuldb.com/vuln/386402/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
