AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19327

MEDIUM · CVSS 5.3 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the getEnrichedData/enrichSession function of the abracadabra50 claude-sesh 1.0.0, allowing local attackers to exploit a manipulation of the sessionId argument, which can lead to path traversal. This could potentially expose sensitive files or data on the system. Organizations using this software should prioritize applying the recommended patch to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19327
Severity
MEDIUM
CVSS
5.3
EPSS
0.14%

Original NVD Description

A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. The attack needs to be launched locally. This patch is called 786c9d74800e6d0858b65778f31beb71b3983a50. Applying a patch is advised to resolve this issue.