Impact
A flaw in the claude-sesh enrichSession function allows an attacker to manipulate the sessionId argument and trigger a path traversal attack when executed locally. This manipulation can result in reading or writing files outside the intended directory, thereby compromising the confidentiality or integrity of local files. The weakness is identified by CWE-22, which signifies a path traversal vulnerability.
Affected Systems
Vendors and products affected include abracadabra50’s claude-sesh, specifically version 1.0.0. No other product versions are listed as impacted by this CVE.
Risk and Exploitability
The CVSS score of 4.8 places this vulnerability in the moderate severity range. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must perform a local launch, meaning the threat is limited to users with local access to the system running claude-sesh. While not exploitable remotely, the moderate CVSS score and local nature suggest that if an attacker gains local foothold—through malware, privilege escalation, or by exploiting another vulnerability—they could leverage this flaw to read or modify arbitrary files on the host. The absence of an EPSS value and KEV listing does not diminish the need for remediation, as a local attacker could still capitalize on the path traversal to compromise data or disrupt operations.
OpenCVE Enrichment