PatchSiren cyber security CVE debrief
CVE-2026-19054 Lspace-io CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary. The evidence for this CVE is limited, and the project was informed of the problem early through an issue report but has not responded yet. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.
- Vendor
- Lspace-io
- Product
- lspace-server
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
Administrators of Lspace-io lspace-server installations; security teams monitoring local access and file API usage; operators and platform teams responsible for Lspace-io lspace-server deployments; vulnerability management teams tracking CVE-2026-19054; security teams reviewing compensating controls for local access restrictions.
Technical summary
The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. The attack is only possible with local access. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.
Defensive priority
Low-priority defensive review recommended due to limited access and low CVSS score.
Recommended defensive actions
- Verify inventory of Lspace-io lspace-server installations
- Monitor for vendor remediation or updates
- Implement compensating controls for local access restrictions
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The evidence for this CVE is limited. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The vulnerability affects Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. The issue is a path traversal vulnerability in the file API, which requires local access. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19054 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19054
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19054 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19054
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Lspace-io/lspace-server/
-
Source reference
Unverified legacy reference
URL: https://github.com/Lspace-io/lspace-server/issues/3
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-19054
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/863836
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/386512
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/386512/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.