PT-2026-69248 · Incomestreamsurfer · Roo-Code-Memory-Bank-Mcp-Server
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
IncomeStreamSurfer roo-code-memory-bank-mcp-server versions up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e
Description
A path traversal issue exists in the
read memory bank file/append memory bank entry component within the src/index.ts file. The flaw occurs in the readMemoryBankFile() and appendMemoryBankEntry() functions when the file name argument is manipulated. This allows a local attacker to access or modify files outside the intended directory. Path traversal is a vulnerability that allows an attacker to use special characters, such as dot-dot-slash (../), to navigate the file system beyond the restricted folder.Recommendations
As a temporary workaround, restrict the use of the
readMemoryBankFile() and appendMemoryBankEntry() functions until a fix is released.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Roo-Code-Memory-Bank-Mcp-Server