VYPR

mcp-memory-keeper

by Mcp Memory Keeper

CVEs (1)

  • CVE-2026-54561medJul 17, 2026
    risk 0.26cvss epss

    ### Impact `context_import` passed the caller-supplied `filePath` directly to `fs.readFileSync` with no path confinement. A malicious MCP client — or an LLM agent that is prompt-injected into calling the tool — could point `filePath` at **any file readable by the server…