PatchSiren

cdeust CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cdeust CVE published 2026-08-14

CVE-2026-49986

CVE-2026-49986 is a high-severity vulnerability in the Cortex MCP server, which allows an attacker to execute arbitrary code with the privileges of the victim's local user process. The vulnerability is caused by the incorrect trust of the `CLAUDE_PROJECT_DIR` environment variable, which can be exploited by placing marker files in a malicious repository.