PatchSiren cyber security CVE debrief
CVE-2026-19054 Lspace-io CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary. The evidence for this CVE is limited, and the project was informed of the problem early through an issue report but has not responded yet. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.
- Vendor
- Lspace-io
- Product
- lspace-server
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
Administrators of Lspace-io lspace-server installations; security teams monitoring local access and file API usage; operators and platform teams responsible for Lspace-io lspace-server deployments; vulnerability management teams tracking CVE-2026-19054; security teams reviewing compensating controls for local access restrictions.
Technical summary
The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. The attack is only possible with local access. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.
Defensive priority
Low-priority defensive review recommended due to limited access and low CVSS score.
Recommended defensive actions
- Verify inventory of Lspace-io lspace-server installations
- Monitor for vendor remediation or updates
- Implement compensating controls for local access restrictions
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The evidence for this CVE is limited. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The vulnerability affects Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. The issue is a path traversal vulnerability in the file API, which requires local access. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then.