Description
MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client, including an LLM agent induced to call the tool, can use ../ traversal or an absolute path to target any file readable by the server process. A valid JSON file is parsed and imported into the caller's session, allowing its full contents to be retrieved through context_get or context_export, while JSON.parse errors for non-JSON files can return leading file bytes in a SyntaxError message. The two disclosure modes can expose other exported sessions, JSON credentials or service-account files, environment files, and portions of SSH keys or other local files. This issue is fixed in version 0.13.0.
Published: 2026-09-15
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local File Read
Action: Patch Now
AI Analysis

Impact

The context_import function in the mcp‑memory‑keeper package passes a caller‑controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An attacker who can invoke this function can provide a relative traversal or an absolute path to any file readable by the MCP server process. If the target file contains valid JSON, its contents are imported into the caller’s session and can later be retrieved via context_get or context_export. If the file is not valid JSON, parsing errors can expose leading bytes of the file in a SyntaxError message. These disclosure modes can expose exported sessions, JSON credentials, service‑account files, environment files, and portions of SSH keys or other local files on the host.

Affected Systems

The mcp‑memory‑keeper package in all releases prior to version 0.13.0 is affected. Users should verify they are not running a vulnerable version and upgrade to 0.13.0 or later, which contains the fix.

Risk and Exploitability

With a CVSS score of 6.2 this vulnerability is rated moderate. The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is through the context_import call, which can be triggered by an MCP client or an LLM agent that has access to the MCP server. If the server process runs with elevated privileges or has access to sensitive files, an attacker could read critical credentials or private keys.

Generated by OpenCVE AI on September 20, 2026 at 15:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade mcp-memory-keeper to version 0.13.0 or later.
  • Disable or restrict the context_import function for untrusted users or client agents.
  • Run the MCP server process with the minimal privileges required, limiting its ability to read sensitive files on the host.

Generated by OpenCVE AI on September 20, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f7wf-v2vw-mpcx mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mkreyman
Mkreyman mcp-memory-keeper
Vendors & Products Mkreyman
Mkreyman mcp-memory-keeper

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client, including an LLM agent induced to call the tool, can use ../ traversal or an absolute path to target any file readable by the server process. A valid JSON file is parsed and imported into the caller's session, allowing its full contents to be retrieved through context_get or context_export, while JSON.parse errors for non-JSON files can return leading file bytes in a SyntaxError message. The two disclosure modes can expose other exported sessions, JSON credentials or service-account files, environment files, and portions of SSH keys or other local files. This issue is fixed in version 0.13.0.
Title MCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePath
Weaknesses CWE-209
CWE-22
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mkreyman Mcp-memory-keeper
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T17:28:58.028Z

Reserved: 2026-06-15T19:04:14.457Z

Link: CVE-2026-54561

cve-icon Vulnrichment

Updated: 2026-09-15T17:28:54.663Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:21.220

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information

  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')