PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19054 Lspace-io CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary. The evidence for this CVE is limited, and the project was informed of the problem early through an issue report but has not responded yet. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.

Vendor
Lspace-io
Product
lspace-server
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Administrators of Lspace-io lspace-server installations; security teams monitoring local access and file API usage; operators and platform teams responsible for Lspace-io lspace-server deployments; vulnerability management teams tracking CVE-2026-19054; security teams reviewing compensating controls for local access restrictions.

Technical summary

The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. The CVSS score is 1.9, indicating a low severity. The attack is only possible with local access. Continuous delivery with rolling releases is used by this product, so no version details of affected nor updated releases are available.

Defensive priority

Low-priority defensive review recommended due to limited access and low CVSS score.

Recommended defensive actions

  • Verify inventory of Lspace-io lspace-server installations
  • Monitor for vendor remediation or updates
  • Implement compensating controls for local access restrictions
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The evidence for this CVE is limited. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The vulnerability affects Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. The issue is a path traversal vulnerability in the file API, which requires local access. The CVSS score is 1.9, indicating a low severity. However, defenders should verify the affected versions and scope with the vendor and primary sources, and monitor for updates. Additionally, they should review compensating controls for local access restrictions and implement them if necessary.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then.