Path Traversal Vulnerability in IncomeStreamSurfer's Memory Bank Server
CVE-2026-19325
4.8MEDIUM
What is CVE-2026-19325?
A vulnerability in IncomeStreamSurfer's memory bank server allows for path traversal through improper handling of the file_name argument within the readMemoryBankFile and appendMemoryBankEntry functions. This flaw enables local attackers to manipulate file paths, potentially gaining unauthorized access to sensitive files outside the intended directories. The vulnerability affects specific versions of the product, which employs a rolling release system, making version updates unpredictable. Despite being alerted to this issue via an early report, the vendor has yet to address the problem publicly.
Affected Version(s)
roo-code-memory-bank-mcp-server 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e
