A vulnerability, which was classified as critical, was found in TinyAGI 0.0.20. Impacted is the function
processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-19010. The attack can be launched remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.