A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMem…
中危 CVSS 5.3
摘要
A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation of the argument file_name leads to path traversal. The attack must be carried out locally. This product utilizes a rolling release system for continuous delivery, and as such, ver…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/IncomeStreamSurfer/roo-code-memory-bank-mcp-server/
- https://github.com/IncomeStreamSurfer/roo-code-memory-bank-mcp-server/issues/7
- https://vuldb.com/cve/CVE-2026-19325
- https://vuldb.com/submit/865242
- https://vuldb.com/vuln/387159
- https://vuldb.com/vuln/387159/cti
时间线
- nvd_ingest NVD