A vulnerability has been found in TinyAGI 0.0.20 and classified as problematic. The affected element is the function
buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion.
This vulnerability was named CVE-2026-19011. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.