Path Traversal Vulnerability in abracadabra50 Claude-Sesh Product
CVE-2026-19327

4.8MEDIUM

Key Information:

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19327?

A vulnerability exists in the abracadabra50 Claude-Sesh product, specifically within the function getEnrichedData/enrichSession located in src/services/enricher.ts. An attacker with local access can exploit this flaw by manipulating the sessionId argument to launch a path traversal attack. This type of attack may allow unauthorized access to filesystem paths, potentially exposing sensitive information. Users are strongly encouraged to apply the latest patch provided (commit 786c9d74800e6d0858b65778f31beb71b3983a50) to secure their systems against this issue.

Affected Version(s)

claude-sesh 1.0.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu03 (VulDB User)
.