Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54561— MCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePath

Quick assessment

Affected
mkreyman mcp-memory-keeper
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MCP Memory Keeper 是一款用于 AI 编码助手中实现持久化上下文管理的 MCP 服务器。在 0.13.0 版本之前, 中的 函数将调用者可控的 直接传递给 ,且未将路径限制在导出目录范围内。MCP 客户端(包括被诱导调用该工具的 LLM 智能体)可以利用 路径遍历或绝对路径,访问服务器进程有权读取的任意文件。有效的 JSON 文件会被解析并导入到调用者的会话中,使其完整内容可以通过 或 获取;而对于非 JSON 文件, 错误会在 SyntaxError 信息中返回文件开头的若干字节。这两种披露方式可

CVSS 6.2 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54561

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePath
Source: CVE Program / CVE List V5
Vulnerability Description
MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client, including an LLM agent induced to call the tool, can use ../ traversal or an absolute path to target any file readable by the server process. A valid JSON file is parsed and imported into the caller's session, allowing its full contents to be retrieved through context_get or context_export, while JSON.parse errors for non-JSON files can return leading file bytes in a SyntaxError message. The two disclosure modes can expose other exported sessions, JSON credentials or service-account files, environment files, and portions of SSH keys or other local files. This issue is fixed in version 0.13.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mkreyman mcp-memory-keeper < 0.13.0 -

II. Public POCs for CVE-2026-54561

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54561

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54561 (3)

Vendor Advisories for CVE-2026-54561 (1)

Proof of Concept for CVE-2026-54561 (1)

Vendor Pages for CVE-2026-54561 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54561

No comments yet


Leave a comment