A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMem…
Medium CVSS 5.3
Summary
A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation of the argument file_name leads to path traversal. The attack must be carried out locally. This product utilizes a rolling release system for continuous delivery, and as such, ver…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/IncomeStreamSurfer/roo-code-memory-bank-mcp-server/
- https://github.com/IncomeStreamSurfer/roo-code-memory-bank-mcp-server/issues/7
- https://vuldb.com/cve/CVE-2026-19325
- https://vuldb.com/submit/865242
- https://vuldb.com/vuln/387159
- https://vuldb.com/vuln/387159/cti
Timeline
- nvd_ingest NVD