Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Tianxi AI Agent PC Application version to 4.2.1.8111 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://iknow.lenovo.com.cn/detail/442249 |
|
Fri, 11 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Potential Command Injection in Lenovo Tianxi AI Agent PC Application |
Thu, 10 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application. | |
| First Time appeared |
Lenovo
Lenovo tianxi Ai Agent Pc Application |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:lenovo:tianxi_ai_agent_pc_application:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo tianxi Ai Agent Pc Application |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-09-10T21:00:19.351Z
Reserved: 2026-08-06T16:32:34.925Z
Link: CVE-2026-19136
No data.
Status : Deferred
Published: 2026-09-10T21:17:24.613
Modified: 2026-09-10T21:34:43.440
Link: CVE-2026-19136
No data.
OpenCVE Enrichment
Updated: 2026-09-11T03:30:16Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')