Impact
The vulnerability resides in the list-project‑files‑validation‑factory.ts component of alioshr memory-bank-mcp up to versions 0.2.1/3.1. An attacker who supplies a crafted projectName argument can traverse file system paths, potentially reading or modifying sensitive files. The flaw is a classic path traversal weakness (CWE‑22). The exploit has been publicly disclosed and may be used by attackers.
Affected Systems
The affected product is alioshr memory-bank-mcp, vulnerable in all versions up to and including 0.2.1/3.1. The attack surface is unknown to the vendor, and no specific subcomponents or modules are listed beyond the file containing the flaw.
Risk and Exploitability
The exploit requires local access to the system where memory-bank-mcp is running; remote exploitation is not possible without local privileges. Based on the description, the likely attack vector is local manipulation of the projectName parameter. The CVSS score of 4.8 indicates moderate severity, and the EPSS score of <1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Consequently, the risk is moderate: any user with local privileges can read or tamper with files via path traversal, but the overall impact is limited to the local system.
OpenCVE Enrichment