<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T20:39:51.882302+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-49986</id>
    <title>CVE-2026-49986 — Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`</title>
    <updated>2026-10-07T20:39:51.884112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> cdeust Cortex</p>
<p>The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is invoked, `_find_dev_source()` resolves the user's active project directory as a candidate Cortex source root. The only validation performed by `_is_cortex_root()` is a check for the presence of an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places these two marker files in a malicious repository can cause Cortex to execute an arbitrary `mcp_server/server/visualize_bootstrap.py` from that directory via `subprocess.run([sys.executable, ...])`, achieving code execution with the privileges of the victim's local user process. Version 3.17.1 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-49986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gvpp-v77h-5w8g</id>
    <title>GHSA-gvpp-v77h-5w8g — Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`</title>
    <updated>2026-10-07T20:39:51.884179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: neuro-cortex-memory</p>
<p>## Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`</p>
<p>### Summary</p>
<p>The Cortex MCP server (`neuro-cortex-memory`) treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is invoked, `_find_dev_source()` resolves the user's active project directory as a candidate Cortex source root. The only validation performed by `_is_cortex_root()` is a check for the presence of an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places these two marker files in a malicious repository can cause Cortex to execute an arbitrary `mcp_server/server/visualize_bootstrap.py` from that directory via `subprocess.run([sys.executable, ...])`, achieving code execution with the privileges of the victim's local user process. CVSS v3.1 Base Score: **7.8 (High)**.</p>
<p>### Details</p>
<p>The vulnerability originates in `_find_dev_source()` inside `mcp_server/handlers/open_visualization.py`. The function builds a list of candidate directories by iterating over the environment variables `CORTEX_DEV_ROOT` and `CLAUDE_PROJECT_DIR`:</p>
<p>```python
# mcp_server/handlers/open_visualization.py:73-76
for env in ("CORTEX_DEV_ROOT", "CLAUDE_PROJECT_DIR"):
    v = os.environ.get(env)
    if v:
        candidates.append(Path(v))
```</p>
<p>`CLAUDE_PROJECT_DIR` is set automatically by the Claude Code IDE extension to whichever directory the user has…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gvpp-v77h-5w8g"/>
  </entry>
</feed>
