Skip to content

MCPA-2026-0040

mediumpath-traversalCVSS 6.2

mcp-memory-keeper arbitrary local file read in context_import via unvalidated filePath (CVE-2026-54561)

mcp-memory-keeper (npm) before 0.13.0: context_import passes the caller-supplied filePath directly to fs.readFileSync with no path confinement — a malicious MCP client or a prompt-injected agent can read any file the server process can access. Fixed in 0.13.0.

Affected packages

EcosystemPackageAffected versions
npmmcp-memory-keeper
>= 0, < 0.13.0

Identifiers

CVE-2026-54561GHSA-f7wf-v2vw-mpcxCWE-22CWE-209

References

Timeline

  • Published: 2026-07-17

← All advisories