Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gvpp-v77h-5w8g | Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` |
Fri, 14 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is invoked, `_find_dev_source()` resolves the user's active project directory as a candidate Cortex source root. The only validation performed by `_is_cortex_root()` is a check for the presence of an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places these two marker files in a malicious repository can cause Cortex to execute an arbitrary `mcp_server/server/visualize_bootstrap.py` from that directory via `subprocess.run([sys.executable, ...])`, achieving code execution with the privileges of the victim's local user process. Version 3.17.1 fixes the issue. | |
| Title | Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-14T16:21:39.125Z
Reserved: 2026-06-02T18:30:51.282Z
Link: CVE-2026-49986
No data.
Status : Received
Published: 2026-08-14T17:18:27.147
Modified: 2026-08-14T17:18:27.147
Link: CVE-2026-49986
No data.
OpenCVE Enrichment
Updated: 2026-08-14T17:30:12Z
Github GHSA