A vulnerability was found in MauricioMilano coder-api up to 1.1.0. It has been rated as critical. Affected is the function
createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection.
This vulnerability is listed as CVE-2026-19284. The attack must be carried out locally. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.