ZeroHour

CVE-2026-19136

mass

Command Injection in Lenovo Tianxi AI Agent PC Application

CVSS 4.0
8.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-19136 is an operating system command injection flaw (CWE-78) in the Tianxi AI Agent PC Application, Lenovo's AI assistant software distributed exclusively in the Chinese market. It is triggered when a local user opens a specially crafted link that is then handled by the application, causing it to execute attacker-controlled OS commands with the user's privileges. Successful exploitation yields high impact to confidentiality, integrity, and availability on the local machine, effectively local code execution without requiring special privileges. All users running the Tianxi AI Agent PC Application are potentially affected; the available data does not specify which version ranges are vulnerable. Exploitation status is currently quiet: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Check the Lenovo PSIRT advisory (CVE-2026-19136) for affected builds and apply the patched Tianxi AI Agent version once published via Lenovo China's official update channel. Until patched, instruct users not to open untrusted or unsolicited links on machines running the agent. Because no proof-of-concept or in-the-wild exploitation is known, this can be remediated as routine high-severity patching rather than an emergency.

Affected
Lenovo Tianxi AI Agent PC Application (China-market exclusive)
Estimated exposure
masslikely millions of installations (preinstalled on Lenovo AI PCs sold in China) — The Tianxi AI Agent ships with Lenovo's China-market AI PC lineup, and Lenovo sells on the order of tens of millions of PCs annually in China, so the installed base is plausibly in the millions; this is a broad estimate, and the exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.

Weakness
CWE-78
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.