CVE-2026-19136
massCommand Injection in Lenovo Tianxi AI Agent PC Application
CVE-2026-19136 is an operating system command injection flaw (CWE-78) in the Tianxi AI Agent PC Application, Lenovo's AI assistant software distributed exclusively in the Chinese market. It is triggered when a local user opens a specially crafted link that is then handled by the application, causing it to execute attacker-controlled OS commands with the user's privileges. Successful exploitation yields high impact to confidentiality, integrity, and availability on the local machine, effectively local code execution without requiring special privileges. All users running the Tianxi AI Agent PC Application are potentially affected; the available data does not specify which version ranges are vulnerable. Exploitation status is currently quiet: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Check the Lenovo PSIRT advisory (CVE-2026-19136) for affected builds and apply the patched Tianxi AI Agent version once published via Lenovo China's official update channel. Until patched, instruct users not to open untrusted or unsolicited links on machines running the agent. Because no proof-of-concept or in-the-wild exploitation is known, this can be remediated as routine high-severity patching rather than an emergency.
| Lenovo Tianxi AI Agent PC Application (China-market exclusive) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.