A vulnerability was found in MauricioMilano coder-api up to 1.1.0. It has been rated as critical. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection.

This vulnerability is listed as CVE-2026-19284. The attack must be carried out locally. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.