Back

HIGH

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application

Published Sep 10, 2026

Description

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.

Affected products

Remediation

Vendor solution

Update Tianxi AI Agent PC Application version to 4.2.1.8111 or later.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner lenovo
Published Sep 10, 2026
Updated Sep 11, 2026
Reserved Aug 6, 2026

CISA Vulnrichment

Updated Sep 11, 2026

NVD

Status Deferred
Modified Sep 11, 2026

Red Hat

No data

ENISA EUVD

Assigner lenovo
Published Sep 10, 2026
Updated Sep 11, 2026

GitHub

No data