Path Traversal Vulnerability in aaronsb Memory-Graph Tool
CVE-2026-19285

4.8MEDIUM

Key Information:

Vendor

Aaronsb

Vendor
CVE Published:
8 August 2026

What is CVE-2026-19285?

Aaronsb memory-graph is susceptible to a path traversal vulnerability within its JsonMemoryStorage functions. The issue affects the createDomain, getMemories, and saveMemories methods in the memoryTools.ts file. This vulnerability allows attackers to exploit the system from a local position and manipulate file paths, potentially leading to unauthorized access to sensitive data. The project operates on a rolling release basis, with no specified version details for affected or updated releases. Despite early notification of this issue through an issue report, the developers have yet to respond.

Affected Version(s)

memory-graph 5cfd2382778837b9f6399080956eee670d00452c

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu02 (VulDB User)
VulDB CNA Team
.