CVE-2026-19285Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. The manipulation results in path traversal. The attack must be initiated from a local position. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 108-08
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-19285 A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.… https://www.cve.org/CVERecord?id=CVE-2026-19285

    Post summary

    The statement merely reports the existence of CVE-2026-19285 affecting a specific function in a library, without providing additional technical details or evidence of exploitation.

    010101.5K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🧠 Memory-graph project hit by path-traversal flaw CVE-2026-19285 affects the memory-graph project's JSON memory-storage functionality. Manipulation of storage parameters can cause path traversal, potentially allowing files to be accessed outside their intended location. The attack requires local access. 📅 Published: August 8 🔎 Source: CVE / Vulners. #AISecurity #MemoryGraph #PathTraversal #CVE #CyberSecurity

    Post summary

    CVE-2026-19285 is a local path‑traversal vulnerability in the memory‑graph project’s JSON storage, potentially exposing files beyond intended directories.

    0000045
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19285 A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.… https://www.cve.org/CVERecord?id=CVE-2026-19285 ----- Traducción: CVE-2026-19285 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-19285 and provides a link to its CVE.org entry, but offers no additional technical details, exploit code, or remediation guidance.

    0000032
    98 followersView on X

Explore more