Path Traversal Vulnerability in IncomeStreamSurfer's Memory Bank Server
CVE-2026-19325

4.8MEDIUM

Key Information:

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19325?

A vulnerability in IncomeStreamSurfer's memory bank server allows for path traversal through improper handling of the file_name argument within the readMemoryBankFile and appendMemoryBankEntry functions. This flaw enables local attackers to manipulate file paths, potentially gaining unauthorized access to sensitive files outside the intended directories. The vulnerability affects specific versions of the product, which employs a rolling release system, making version updates unpredictable. Despite being alerted to this issue via an early report, the vendor has yet to address the problem publicly.

Affected Version(s)

roo-code-memory-bank-mcp-server 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu03 (VulDB User)
VulDB CNA Team
.