CVE-2026-19136: Lenovo Tianxi Ai Agent Pc Application

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.

Affected products

  • Lenovo Tianxi Ai Agent Pc Application: before 4.2.1.8111 (fixed in 4.2.1.8111)

Published 2026-09-10. Last modified 2026-09-11.