PT-2026-43082 · Unknown · Cline-Mcp-Memory-Bank

·

CVE-2026-9468

·

Published

2026-05-25

·

Updated

2026-05-25

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dazeb cline-mcp-memory-bank versions up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f
Description A remote path traversal flaw exists in the handleInitializeMemoryBank() function within the src/index.ts file. This issue occurs when the projectPath argument is manipulated, allowing an attacker to access files or directories outside the intended folder.
Recommendations As a temporary workaround, restrict or validate the input provided to the projectPath argument in the handleInitializeMemoryBank() function to prevent path traversal. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9468

Affected Products

Cline-Mcp-Memory-Bank