PatchSiren cyber security CVE debrief
CVE-2026-19327 abracadabra50 CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T03:16:57.057Z and has not been modified since then. The vulnerability affects abracadabra50 claude-sesh 1.0.0 product, specifically the function getEnrichedData/enrichSession in src/services/enricher.ts, allowing for path traversal attacks. The attack needs to be launched locally. Users should verify and apply patches. The patch is called 786c9d74800e6d0858b65778f31beb71b3983a50. The evidence for this CVE is limited, and users should review compensating controls for exposed systems while remediation is scheduled and verified.
- Vendor
- abracadabra50
- Product
- claude-sesh
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-09
- Original CVE updated
- 2026-08-09
- Advisory published
- 2026-08-09
- Advisory updated
- 2026-08-09
Who should care
Users of abracadabra50 claude-sesh 1.0.0; verify and apply patches. Users should also review compensating controls for exposed systems while remediation is scheduled and verified. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Technical summary
The function getEnrichedData/enrichSession in src/services/enricher.ts has a path traversal vulnerability. This issue affects the abracadabra50 claude-sesh 1.0.0 product. The attack needs to be launched locally. Applying a patch is advised to resolve this issue. The patch is called 786c9d74800e6d0858b65778f31beb71b3983a50. The vulnerability allows attackers to manipulate the argument sessionId, leading to path traversal. Users should verify the affected scope and apply patches. Monitor for exploitation attempts.
Defensive priority
Local attackers may attempt path traversal attacks; verify and apply patches.
Recommended defensive actions
- Verify and apply patches
- Monitor for exploitation attempts
- Perform inventory checks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The evidence for this CVE is limited. The CVE record was published on 2026-08-09T03:16:57.057Z and has not been modified since then. Users should verify the affected scope and apply patches. Monitor for exploitation attempts. The function getEnrichedData/enrichSession in src/services/enricher.ts has a path traversal vulnerability.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T03:16:57.057Z and has not been modified since then.