PT-2026-69250 · Unknown · Claude-Sesh

·

CVE-2026-19327

·

Published

2026-08-09

·

Updated

2026-08-11

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions abracadabra50 claude-sesh version 1.0.0
Description A flaw in the enrichSession function within getEnrichedData (located in the src/services/enricher.ts file) allows for path traversal. This occurs when the sessionId argument is manipulated. Path traversal is a technique used to access files and directories that are stored outside the web root folder. This issue requires the attack to be launched locally.
Recommendations Apply patch 786c9d74800e6d0858b65778f31beb71b3983a50 for version 1.0.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19327

Affected Products

Claude-Sesh