AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19285

MEDIUM · CVSS 5.3 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability in aaronsb memory-graph affects the JsonMemoryStorage functions, allowing for potential path traversal attacks when exploited locally. This could lead to unauthorized access to sensitive files within the system. Organizations using this software should prioritize addressing this issue, especially those with local access controls in place, as the risk of exploitation is contingent on local user privileges.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19285
Severity
MEDIUM
CVSS
5.3
EPSS
0.14%

Original NVD Description

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. The manipulation results in path traversal. The attack must be initiated from a local position. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.