PatchSiren

Lspace-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Lspace-io CVE published 2026-08-06

CVE-2026-19054

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:52.560Z and has not been modified since then. The Lspace-io lspace-server has a path traversal vulnerability in the file API, which requires local access. The vulnerability affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repo [truncated]