PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15524 alioshr CVE debrief

A path traversal vulnerability was detected in alioshr memory-bank-mcp up to 0.2.1/3.1. The issue affects an unknown part of the file list-project-files-validation-factory.ts. Manipulation of the argument projectName leads to path traversal. Local access is required to approach this attack. This vulnerability has a low CVSS score of 1.9 and is considered low severity. The CVE record was published on 2026-07-13T03:16:16.513Z and has not been modified since then.

Vendor
alioshr
Product
memory-bank-mcp
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-13
Original CVE updated
2026-07-13
Advisory published
2026-07-13
Advisory updated
2026-07-13

Who should care

Users of alioshr memory-bank-mcp up to 0.2.1/3.1 should be aware of this path traversal vulnerability. Operators, platform administrators, vulnerability management teams, and security teams should review the affected scope and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

The vulnerability is caused by improper handling of the projectName argument in the list-project-files-validation-factory.ts file. This allows for path traversal attacks, which can be exploited with local access. The vulnerability affects alioshr memory-bank-mcp up to 0.2.1/3.1. Users should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Defensive priority

Low priority due to local access requirement and low CVSS score. However, users should still review the affected scope and vendor guidance to ensure proper mitigation.

Recommended defensive actions

  • Inventory affected systems for compensating controls
  • Monitor for suspicious local activity
  • Apply vendor remediation when available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-13T03:16:16.513Z and has not been modified since then. The NVD entry is currently Received. The vulnerability affects an unknown part of the file list-project-files-validation-factory.ts in alioshr memory-bank-mcp up to 0.2.1/3.1. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. Users should verify the affected scope and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15524 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15524

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15524 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15524

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.