PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19054 Lspace-io CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary. The evidence for this CVE is limited, and the project was informed of the problem early through an issue report but has not responded yet. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.

Vendor
Lspace-io
Product
lspace-server
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Administrators of Lspace-io lspace-server installations; security teams monitoring local access and file API usage; operators and platform teams responsible for Lspace-io lspace-server deployments; vulnerability management teams tracking CVE-2026-19054; security teams reviewing compensating controls for local access restrictions.

Technical summary

The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. The attack is only possible with local access. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.

Defensive priority

Low-priority defensive review recommended due to limited access and low CVSS score.

Recommended defensive actions

  • Verify inventory of Lspace-io lspace-server installations
  • Monitor for vendor remediation or updates
  • Implement compensating controls for local access restrictions
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The evidence for this CVE is limited. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The vulnerability affects Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. The issue is a path traversal vulnerability in the file API, which requires local access. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19054 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19054

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19054 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19054

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.