A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This manipulation causes file inclusion. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
TinyAGI version 0.0.20 contains a critical file inclusion vulnerability in the Message API Endpoint's collectFiles function (packages/core/src/response.ts). This weakness allows attackers to manipulate file handling logic, enabling remote file inclusion attacks that could lead to unauthorized file access, information disclosure, or code execution. The vulnerability affects any deployment running the vulnerable version, particularly systems exposing the Message API to untrusted networks. With a CVSS score of 7.3 and public exploit availability, this represents an active threat requiring immediate patching or network segmentation.
While this CVE does not map to specific MITRE ATT&CK techniques in the initial disclosure, Casky's AI-driven analysis would identify attack patterns consistent with Execution (T1059 - Command Line Interface, T1203 - Exploitation for Client Execution) and Defense Evasion (T1036 - Masquerading) techniques. Security practitioners using Casky would observe detection signals around abnormal file access patterns in the response.ts component, suspicious collectFiles function calls with path traversal indicators, and unexpected file read/write operations originating from the Message API Endpoint. The platform's 754 mapped security skills would flag code-level weaknesses in input validation and file path sanitization, enabling teams to correlate this vulnerability with similar file inclusion patterns across their infrastructure and prioritize remediation based on exposure analysis.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-19009. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation