Impact
The context_import function in the mcp‑memory‑keeper package passes a caller‑controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An attacker who can invoke this function can provide a relative traversal or an absolute path to any file readable by the MCP server process. If the target file contains valid JSON, its contents are imported into the caller’s session and can later be retrieved via context_get or context_export. If the file is not valid JSON, parsing errors can expose leading bytes of the file in a SyntaxError message. These disclosure modes can expose exported sessions, JSON credentials, service‑account files, environment files, and portions of SSH keys or other local files on the host.
Affected Systems
The mcp‑memory‑keeper package in all releases prior to version 0.13.0 is affected. Users should verify they are not running a vulnerable version and upgrade to 0.13.0 or later, which contains the fix.
Risk and Exploitability
With a CVSS score of 6.2 this vulnerability is rated moderate. The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is through the context_import call, which can be triggered by an MCP client or an LLM agent that has access to the MCP server. If the server process runs with elevated privileges or has access to sensitive files, an attacker could read critical credentials or private keys.
OpenCVE Enrichment
Github GHSA